The edtech sector is facing renewed scrutiny following Instructure’s decision to reach an agreement – widely believed to involve a ransom payment – with the hacking group ShinyHunters after suffering two data breaches. This incident highlights the escalating risks and difficult choices facing organizations when dealing with cyberattacks, particularly those handling sensitive student data.
What Happened
Instructure, the company behind the Canvas learning management system used by nearly 9,000 schools, was breached twice in recent months. ShinyHunters claimed responsibility for the initial breach on April 29th, alleging the theft of data on 275 million individuals. Following a second breach involving defacement of Canvas login pages, the hackers demanded a ransom. Instructure announced an “agreement” with the hackers on Monday, stating that evidence of data destruction had been provided and customers would not be extorted. While the financial terms remain undisclosed, the removal of the stolen data listing from ShinyHunters’ leak site strongly suggests a payment was made. ShinyHunters has since claimed the data has been deleted.
This incident mirrors a 2024 breach at PowerSchool, another major edtech provider, which also opted to pay a ransom, only to have some customers subsequently extorted by a different group with remaining stolen data. The FBI has issued warnings against paying ransoms, advising victims not to engage with cybercriminals.
The stolen data included student names, personal email addresses, and private communications between teachers and students, raising significant privacy concerns.
Why It Matters
This case is particularly troubling because it demonstrates the potential futility of paying ransoms. PowerSchool's experience shows that even after a payment, data can remain in the hands of malicious actors and be used for further extortion. For developers and security teams, this underscores the importance of robust data protection measures and incident response plans. The fact that Instructure experienced two breaches raises questions about the effectiveness of its security posture and incident response.
Beyond the immediate financial cost of a ransom, these breaches can inflict significant reputational damage and erode trust in edtech platforms. Schools and institutions are increasingly reliant on these systems, making them attractive targets for financially motivated cybercriminals. The incident also highlights the complexities of negotiating with criminals – Instructure acknowledges there’s “never complete certainty” when dealing with them. The lack of transparency regarding the agreement, including the amount paid and the specifics of the data destruction verification, is also concerning.
What To Watch
Several key questions remain unanswered. It is unclear who within Instructure is responsible for cybersecurity oversight, and whether there will be any leadership changes following these breaches. The full extent of the data compromised and the potential long-term impact on students and staff are still being assessed.
More broadly, this incident will likely intensify the debate over the ethics and effectiveness of paying ransoms. We can expect increased scrutiny of security practices in the edtech sector and potentially increased regulatory pressure to improve data protection. It will be important to monitor whether ShinyHunters, or other groups, adhere to their claims of data deletion, and whether Instructure customers face further threats.