Key Takeaways

- Instructure reached a deal with hackers to delete data stolen from Canvas, though experts doubt the data is truly gone
- ShinyHunters claimed to have breached 9,000 schools and accessed data on 275 million individuals
- Stolen data included student IDs, emails, names, and messages, but not passwords or financial information
Instructure, the company behind the widely used Canvas learning management system, announced it reached an agreement with hackers to delete data stolen in a cyberattack that disrupted finals week for students across nearly 9,000 schools worldwide.
The company did not disclose whether it paid a ransom. But former FBI Cyber Division deputy director Cynthia Kaiser said the reported deal suggests payment was likely made.
“What victims must understand is that payment does not end the threat. Stolen data will be used against clients and users for as long as it remains profitable to do so.”
— Cynthia Kaiser, Senior Vice President, Halcyon Ransomware Research Center
What ShinyHunters Stole
A hacking group called ShinyHunters claimed responsibility for last week's breach. The group threatened to leak data involving 275 million individuals if schools did not pay a ransom by May 6. When the deadline passed, ShinyHunters extended it, indicating some schools had started negotiating.
This isn't ShinyHunters' first attack on Instructure. The group was behind a smaller breach of the company last year.
Steve Proud, Instructure's chief information security officer, said the breach appeared to involve student ID numbers, email addresses, names, and messages on the Canvas platform. The company found no evidence that passwords, dates of birth, government identification, or financial information were compromised.
The Deal and Its Limits
Instructure said it received "digital confirmation" that the hackers destroyed remaining copies of the data. This confirmation came in the form of "shred logs." The company was blunt about the limits of this assurance.
"While there is never complete certainty when dealing with cybercriminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible," Instructure wrote in its online post.
Cybersecurity experts remain skeptical. There's no technical mechanism that forces criminals to honor deletion promises. Shred logs can be fabricated. And data can be copied to offline storage before any deletion occurs.
Chaos During Finals Week
The timing of the attack caused maximum disruption. Instructure temporarily took Canvas offline while investigating, locking out students and faculty during finals. Many students rely on Canvas for submitting assignments, accessing course materials, and communicating with instructors.
A lawsuit filed last week in federal court in Utah alleged Instructure did not do enough to protect the platform and made itself "easy prey for cybercriminals." The suit claims the company failed millions of students who depend on the platform.
What Happens Now
Instructure said it is working with "expert vendors" to conduct a forensic analysis, strengthen its systems, and complete a "comprehensive review of the data involved."
For affected users, the immediate risk appears limited. No passwords or financial data were taken. But email addresses and student IDs can fuel phishing attacks. Students and faculty at affected schools should watch for suspicious emails claiming to be from their institution or Canvas.
Related security news about platform vulnerabilities
Logicity's Take
Frequently Asked Questions
Was Canvas data actually deleted by hackers?
Instructure says it received 'shred logs' as confirmation. But cybersecurity experts note there's no way to verify that criminals truly deleted all copies. Data can be stored offline or shared before any deletion occurs.
What information was stolen in the Canvas breach?
According to Instructure, the breach involved student ID numbers, email addresses, names, and messages on Canvas. The company says passwords, dates of birth, government IDs, and financial information were not compromised.
How many people were affected by the Canvas hack?
ShinyHunters claimed to have accessed data on 275 million individuals across nearly 9,000 schools worldwide.
Who is ShinyHunters?
ShinyHunters is a hacking group that has been active for several years. They previously breached Instructure in a smaller attack and have targeted numerous other organizations with ransomware and data theft.
Should Canvas users change their passwords?
Instructure says passwords were not compromised in this breach. However, users should remain alert for phishing emails that might use stolen information like names and email addresses to appear legitimate.
Need Help Implementing This?
Source: mint
Manaal Khan
Tech & Innovation Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.
Related Articles
More in Trending Tech
AI Revolution: How Tech is Transforming the World, One Industry at a Time
From desalination plants in Iran to AI-powered manufacturing, the tech world is abuzz with innovation. Discover how AI is changing the game for small entrepreneurs and what it means for the future of industry. Explore the latest developments in cybersecurity, robotics, and more.

Revolutionizing AI: The Game-Changing Tech That's Making Agents Smarter
A new technology is set to revolutionize the way AI agents learn and adapt, enabling them to accumulate wisdom and apply it to new situations. This innovation has the potential to significantly boost the reliability of AI agents, especially in complex tasks. By converting raw agent trajectories into reusable guidelines, this tech is poised to transform the AI landscape.

The Dark Side of AI: How Bots Are Fueling a Monetized Abuse Ecosystem
A recent analysis of 2.8 million Telegram messages reveals a shocking truth: AI-powered bots are being used to create and sell non-consensual intimate images. These bots can turn ordinary photos into synthetic nude images, and the abuse is being monetized through affiliate programs and subscription-based archives. The researchers behind the study are calling for stricter regulations to combat this growing problem.

AI's Secret Sauce: How Journalism Became the Unlikely Ingredient
A recent study reveals that AI chatbots rely heavily on journalistic sources for their quotes, with one in four coming from news outlets. This shocking discovery has significant implications for the media industry and our understanding of AI's information gathering processes. As AI technology continues to evolve, it's essential to consider the role of journalism in shaping its responses.



