Ask Onix
Instructure strikes deal with cybercriminals after massive breach
Instructure, the company behind the widely used Canvas learning platform, has confirmed it reached an agreement with hackers to prevent the release of 3.5 terabytes of stolen student and university data. The breach disrupted operations at approximately 9,000 educational institutions across the U.S., Canada, Australia, and the U.K.
Scope of the attack
The cyberattack, discovered on April 29, was claimed by the Shiny Hunters extortion group. The incident caused widespread disruptions, particularly during exam periods, as students and faculty lost access to the platform. Some online exams were interrupted, forcing universities to postpone assessments.
Aubrey Palmer, a meteorology student at Mississippi State University, described the chaos when a ransom note suddenly appeared on screens during an exam. "My knee-jerk reaction was that I'd been hacked myself," Palmer told the BBC. "But then I read the note and saw it was Canvas that had been targeted." The message threatened to publish stolen data unless a bitcoin ransom was paid.
Terms of the agreement
Instructure stated that its primary motivation was protecting student and staff data. While the company did not disclose the specifics of the deal, it confirmed the hackers had agreed to delete the stolen data and refrain from further extortion. "While there is never complete certainty when dealing with cyber criminals, we believe it was important to take every step within our control to give customers additional peace of mind," the company said in a statement.
Law enforcement agencies globally advise against paying ransoms, as it encourages further attacks and offers no guarantee that data will be destroyed. Past cases, such as the takedown of the LockBit ransomware group, revealed that criminals often retain stolen data even after receiving payments.
Shiny Hunters' track record
The Shiny Hunters group, known for targeting high-profile organizations, has been linked to previous breaches, including attacks on Jaguar Land Rover and Gucci. The group, believed to consist of young, English-speaking hackers, has a history of pressuring victims into paying ransoms in bitcoin.
In encrypted messages with the BBC, the group claimed to have breached Canvas twice before the April 29 attack. Instructure had previously disclosed a breach in September 2025, and Shiny Hunters alleged another intrusion in April 2026. When asked about the stress caused to students like Palmer, the group declined to comment.
Industry concerns over ransom payments
Instructure's decision to pay the hackers has drawn attention due to its rarity-most victims avoid publicly acknowledging such payments. The company's transparency, however, may stem from the high visibility of the attack and its direct impact on students. Experts warn that paying ransoms can perpetuate the cycle of cybercrime, as criminals often re-target victims or sell data despite promises to delete it.