**
The recent cyber assault on Instructure, the tech firm behind the widely used educational platform Canvas, has reignited the contentious debate surrounding ransom payments to hackers. With the personal data of millions at stake, including details from 9,000 schools and 275 million students and staff members, the company’s decision to negotiate with its attackers raises critical questions about the ethics and effectiveness of paying ransoms in the face of escalating cyber threats.
The Attack and Its Fallout
Instructure’s predicament unfolded after hackers, identifying themselves as ShinyHunters, breached its systems, stealing a staggering 3.6 terabytes of sensitive data. This breach resulted in significant operational disruptions, forcing many educational institutions to alter assignment deadlines and grapple with compromised login portals. As students struggled to access their coursework, Instructure’s covert negotiations with the hackers led to speculation that a ransom had been settled, a detail the company has not publicly confirmed.
Experts have scrutinised Instructure’s public statements, interpreting the language used as indicative of an agreement reached with the hackers. The firm reported that the stolen data was “returned” as part of this agreement and claimed to have received “digital confirmation of data destruction” through shred logs—technical documentation indicating that the data had been irretrievably deleted. However, this assurance does little to quell the broader concerns around the reliability of cybercriminals.
The Ethical Quandary of Paying Ransoms
The dilemma faced by companies like Instructure is emblematic of a larger trend, as businesses worldwide grapple with the decision of whether to comply with ransom demands. Despite widespread governmental advisories against such payments—including from authorities in the UK, US, and Australia—many organisations still opt to pay. A report by Akamai highlights that while outright bans on ransom payments are uncommon, the risks associated with compliance are substantial. Paying a ransom not only fuels future cybercriminal activities but also does not guarantee the safeguarding of sensitive data.
In Australia, the legal landscape complicates this issue further. Under the autonomous cyber sanctions law, paying designated attackers could be prosecuted, although the government evaluates each case individually. Recent data indicates that as of January 2026, 75 businesses with turnovers exceeding $3 million had paid ransoms, with the average payment amounting to approximately $711,000—down from $1.35 million the previous year.
Risk Management in Cybersecurity
As the frequency and severity of cyberattacks rise, companies are beginning to improve their cybersecurity postures, which may reduce their reliance on ransom payments. Darren Hopkins, head of cyber at McGrathNicol, notes a shift in focus; rather than solely attempting to unlock systems, businesses are increasingly prioritising damage control efforts to prevent data breaches.
The question of trust remains paramount in these negotiations. Hopkins points out that many executives ask whether paying a ransom will genuinely halt the exposure of their data. This uncertainty reflects a broader mistrust of the criminal enterprises that orchestrate these attacks. While hackers like ShinyHunters may have an incentive to maintain a façade of reliability to encourage future payments, the inherent nature of their operations raises serious doubts about their integrity.
The Future of Ransom Payments
The debate over ransom payments is far from settled. As organisations become more adept at preparing for and mitigating cyber threats, the landscape may continue to evolve. However, as long as the potential for lucrative payoffs exists, the cycle of ransomware attacks is likely to persist.
Instructure’s experience serves as a cautionary tale for companies navigating the murky waters of cybercrime. The decision to engage with criminals, even with the best intentions of safeguarding user data, carries significant risks. The aftermath of such negotiations may not only impact the immediate victims but also shape the future behaviours of both businesses and cybercriminals alike.
Why it Matters
The ongoing discourse surrounding ransom payments highlights a critical inflection point in the cybersecurity landscape. As the stakes rise, businesses must weigh the immediate benefits of compliance against the long-term implications of empowering criminal organisations. The Instructure case exemplifies the difficult choices organisations face in protecting sensitive data while navigating ethical and legal minefields. Ultimately, the decisions made in the coming years will shape the future of cybersecurity practices and the integrity of digital infrastructures on which we all rely.