In the largest educational cybersecurity breach on record, Instructure — the company behind Canvas LMS, used by 41% of North American higher education institutions — has confirmed it paid a ransom to criminal extortion group ShinyHunters after two damaging hacks within ten days. The breach exposed data belonging to approximately 275 million users across 8,809 institutions worldwide — and the decision to negotiate with hackers has ignited a fierce debate about whether paying ransoms protects victims or simply emboldens future attacks.
The Timeline: Two Hacks, Ten Days, and a Ransom Deal
- →April 29 — Instructure detects unauthorised activity in Canvas and revokes third-party access
- →May 2 — Instructure states it has contained the incident; confirms names, email addresses, student ID numbers, and messages were stolen
- →May 3 — ShinyHunters publishes a ransom letter claiming responsibility, threatening to leak data if Instructure does not engage by May 6
- →May 6 — Instructure declares Canvas fully operational; applies security patches without negotiating with hackers
- →May 7 — ShinyHunters strikes again: Canvas login pages across hundreds of institutions are replaced with a defacement message — live to millions of students during final exam season
- →May 11 — CEO Steve Daly issues a public apology for lack of transparency; Instructure confirms it has reached an agreement with "the unauthorised actor"
- →May 12 — Instructure states it received digital confirmation of data destruction and that no customers will be extorted further — hours before ShinyHunters' final deadline
What Was Stolen and How Did ShinyHunters Get In?
ShinyHunters exploited a vulnerability in Instructure's Free-For-Teacher (F4T) accounts — a complimentary tier of Canvas used by educators — to obtain initial access and siphon approximately 3.65 terabytes of data from around 275 million users. Instructure later confirmed that the second hack in May was caused by the same underlying vulnerability it had failed to fully patch after the first incident.
The data exposed included names, institutional email addresses, student ID numbers, course enrollments, and private Canvas inbox messages between students and teachers. ShinyHunters described the dataset as containing "several billions of private messages." Instructure confirmed it found no evidence that passwords, dates of birth, government identifiers, or financial information were compromised — but given the personal nature of the messages involved, the breach represents a significant privacy violation at a scale that has no precedent in education technology.
The breach affected 8,809 universities, educational ministries, and other institutions worldwide — including all eight Ivy League universities, major US state systems, and institutions across the UK, Canada, Australia, and New Zealand. It has been confirmed as the largest educational cybersecurity breach on record.
"Over the past few days, many of you dealt with real disruption. Stress on your teams. Missed moments in the classroom. Questions you couldn't get answered. You deserved more consistent communication from us and we didn't deliver it. I'm sorry for that."— Steve Daly, CEO, Instructure
Why Did Instructure Pay? The Reasoning Explained
Instructure was explicit about its reasoning. On its incident update page, the company stated: "We know that concerns about the potential publication of data related to this incident remain top of mind for many customers. We understand how unsettling situations like this can be, and protecting our community remains our top priority. With that responsibility in mind, Instructure reached an agreement with the unauthorised actor involved in this incident."
The company said it received "digital confirmation of data destruction (shred logs)" and assurance that no Instructure customers would be extorted as a result of the incident. It specified that the agreement covers all impacted customers and that individual institutions have no need to engage with ShinyHunters directly.
Instructure did not explicitly confirm a cash payment — but the timing of the statement (hours before ShinyHunters' May 12 deadline), the removal of the company from the hackers' dark web leak site, and the language of the announcement all point strongly toward a financial settlement having been made.
The Controversy: Does Paying Ransom Make Anyone Safer?
The cybersecurity community's response has been unambiguous: paying ransoms is problematic — legally, strategically, and ethically. Regulatory guidance in most jurisdictions discourages or restricts ransom payments on the grounds that they fund criminal operations, confirm that extortion works, and drive up demand for future attacks. The general advice from law enforcement, including the FBI and CISA — both of which were notified by Instructure — is consistently not to pay.
The deeper problem is that there is no reliable way to verify any criminal's claim of data destruction. Even when hackers provide shred logs or similar "proof," the history of ransomware and extortion incidents is full of cases where data was retained, resold, or used in subsequent attacks months or years later — often against the same organisation that paid.
"Even when criminals claim they've deleted stolen data or provide 'proof' of destruction, there is no reliable way to verify those claims, and history shows that data is often retained, resold, or used in future extortion attempts. From a risk perspective, organizations may be trading a visible short-term disruption for a longer-term exposure problem that can resurface months or years later."— Cliff Steinhauer, Cybersecurity Expert
Instructure itself acknowledged these limits — stating plainly that there is "always uncertainty when dealing with cyber criminals" — while framing the payment as a decision made in the interests of giving its community peace of mind. That framing will not satisfy critics, but it reflects the impossible position institutions face when millions of users' private data hangs in the balance.
Impact on Students, Staff, and Institutions
The timing of the May 7 attack could hardly have been worse. Students across North America were in the middle of final exam periods and end-of-semester assignment deadlines when the Canvas login screen was replaced with a ransom note. At Arizona State University, finals were disrupted; the University of California system instructed its campuses to block Canvas access as a precaution; Sacramento State students were redirected to ShinyHunters' extortion message when attempting to log in.
For many institutions, the breach exposed names, email addresses, student ID numbers, course enrollments, and private messages — data that, while not as financially sensitive as passwords or financial records, carries real risks of identity fraud, phishing, and social engineering targeted at students and educators. North Carolina's Department of Public Instruction blocked Canvas access statewide as an additional precaution.
Following the ransom agreement, Instructure shut down all Free-For-Teacher accounts — the vector through which ShinyHunters gained initial access — and confirmed it had notified the FBI, CISA, and international law enforcement partners. The company also acknowledged the breach was caused by the same vulnerability it had failed to fully address after the first incident in late April.
