Teaching software company strikes a deal with hackers to get customer data back, defying FBI guidance

Instructure, an education technology company, has reached an agreement with ShinyHunters, the hacker group responsible for breaching its Canvas learning management system for the second time this month. The attack compromised the personal information of approximately 280 million Canvas users, including names, email addresses, and private messages. ShinyHunters issued a May 12 deadline and threatened to publicly release the stolen data unless Instructure made contact with the group. Following negotiations, Instructure reports that the hackers have returned the exfiltrated data as part of the settlement.

The company’s decision to negotiate with the attackers represents a departure from law enforcement guidance, as the FBI typically advises organizations against engaging with or paying ransoms to hacker groups. Such agreements can inadvertently incentivize further attacks and complicate criminal investigations. The breach is particularly concerning given that it marks the second successful compromise of Instructure’s systems, raising questions about the effectiveness of the company’s security infrastructure and incident response procedures. Canvas, widely used by educational institutions globally, serves millions of students and educators, making the exposure of this data a significant incident affecting a substantial user base. The incident underscores the ongoing challenge organizations face when balancing immediate data recovery against compliance with law enforcement recommendations.

Sources