In an age where cyber threats loom large, the dilemma of whether to pay ransoms to hackers has surged to the forefront of discussions among businesses worldwide. Recent events surrounding the US educational platform Canvas have placed this issue under the spotlight, raising questions about the safety of sensitive data and the ethics of yielding to cybercriminals.
The Canvas Incident: A Wake-Up Call for Education Providers
After enduring a tumultuous week of outages, the tech firm Instructure, which operates the widely used Canvas platform, revealed it had “reached an agreement” with the hackers responsible for a massive ransomware attack. This breach compromised the data of approximately 275 million students and staff across 9,000 educational institutions, with the hackers threatening to leak 3.6 terabytes of sensitive information unless their demands were met.
Experts speculate that this carefully crafted announcement strongly hints at the payment of a ransom, although Instructure has yet to confirm this. The repercussions of the attack were felt across numerous Australian universities and schools, with institutions like RMIT and UTS forced to extend assignment deadlines due to inaccessible systems.
The Hacker’s Playbook: Understanding the Threat
Claiming responsibility for the breach, the hacking group ShinyHunters demonstrated their modus operandi of extortion. They exploited a vulnerability in Instructure’s Free for Teacher software, managing to deface login pages and further alert users to the security breach. Instructure stated that the data was “returned” following their agreement with the hackers and that they received assurances of data destruction via technical logs.
“While there is never complete certainty when dealing with cybercriminals, we believe it was important to take every step within our control to give customers additional peace of mind,” remarked the company, highlighting the precarious position they faced.
To Pay or Not to Pay: The Ongoing Debate
The debate over whether to pay ransoms is far from straightforward. Governments in the UK, US, and Australia generally advise against such payments, yet they remain a common recourse for many businesses facing cyber extortion. A recent report revealed that 75 Australian businesses with annual turnovers exceeding £3 million had paid ransoms by January 2026, with the average payment now standing at £711,000—down significantly from £1.35 million the previous year.
Experts like Darren Hopkins from McGrathNicol emphasise that while businesses are becoming savvier in their cyber defences, the immediate fear of data exposure often leads them to negotiate with hackers. “Canvas was intriguing because it appeared Instructure engaged with the threat actor swiftly, likely to prevent the leak,” he noted.
The Trust Factor: Can Hackers Be Trusted?
The pressing question remains: if a ransom is paid, can businesses trust that the criminals will indeed delete the data as promised? This uncertainty is echoed in boardrooms across sectors, with executives grappling with the moral implications of paying ransoms to those they consider criminals.
Luke Irwin, a cybersecurity expert, points out that while it may be in ShinyHunters’ interest to maintain a façade of good faith to attract future victims, the risk of being double-crossed always exists. “One can’t rely on them to act outside their criminal nature,” he cautioned, highlighting the inherent risks involved.
Why it Matters
As cyber threats continue to escalate, the dilemma over ransom payments has significant implications for businesses and individuals alike. This incident serves as a stark reminder of the vulnerabilities that exist in our digital landscape and the ethical quandaries faced by organisations when their data security is compromised. Ultimately, the choices made today will shape the future of cybercrime and the measures needed to safeguard sensitive information in an increasingly interconnected world.