Ransomware Dilemma: Should Companies Pay to Retrieve Stolen Data?

Alex Turner, Technology Editor
5 Min Read
⏱️ 3 min read

In an age where cyber threats loom large, the dilemma of whether to pay ransoms to hackers has surged to the forefront of discussions among businesses worldwide. Recent events surrounding the US educational platform Canvas have placed this issue under the spotlight, raising questions about the safety of sensitive data and the ethics of yielding to cybercriminals.

The Canvas Incident: A Wake-Up Call for Education Providers

After enduring a tumultuous week of outages, the tech firm Instructure, which operates the widely used Canvas platform, revealed it had “reached an agreement” with the hackers responsible for a massive ransomware attack. This breach compromised the data of approximately 275 million students and staff across 9,000 educational institutions, with the hackers threatening to leak 3.6 terabytes of sensitive information unless their demands were met.

Experts speculate that this carefully crafted announcement strongly hints at the payment of a ransom, although Instructure has yet to confirm this. The repercussions of the attack were felt across numerous Australian universities and schools, with institutions like RMIT and UTS forced to extend assignment deadlines due to inaccessible systems.

The Hacker’s Playbook: Understanding the Threat

Claiming responsibility for the breach, the hacking group ShinyHunters demonstrated their modus operandi of extortion. They exploited a vulnerability in Instructure’s Free for Teacher software, managing to deface login pages and further alert users to the security breach. Instructure stated that the data was “returned” following their agreement with the hackers and that they received assurances of data destruction via technical logs.

“While there is never complete certainty when dealing with cybercriminals, we believe it was important to take every step within our control to give customers additional peace of mind,” remarked the company, highlighting the precarious position they faced.

To Pay or Not to Pay: The Ongoing Debate

The debate over whether to pay ransoms is far from straightforward. Governments in the UK, US, and Australia generally advise against such payments, yet they remain a common recourse for many businesses facing cyber extortion. A recent report revealed that 75 Australian businesses with annual turnovers exceeding £3 million had paid ransoms by January 2026, with the average payment now standing at £711,000—down significantly from £1.35 million the previous year.

Experts like Darren Hopkins from McGrathNicol emphasise that while businesses are becoming savvier in their cyber defences, the immediate fear of data exposure often leads them to negotiate with hackers. “Canvas was intriguing because it appeared Instructure engaged with the threat actor swiftly, likely to prevent the leak,” he noted.

The Trust Factor: Can Hackers Be Trusted?

The pressing question remains: if a ransom is paid, can businesses trust that the criminals will indeed delete the data as promised? This uncertainty is echoed in boardrooms across sectors, with executives grappling with the moral implications of paying ransoms to those they consider criminals.

Luke Irwin, a cybersecurity expert, points out that while it may be in ShinyHunters’ interest to maintain a façade of good faith to attract future victims, the risk of being double-crossed always exists. “One can’t rely on them to act outside their criminal nature,” he cautioned, highlighting the inherent risks involved.

Why it Matters

As cyber threats continue to escalate, the dilemma over ransom payments has significant implications for businesses and individuals alike. This incident serves as a stark reminder of the vulnerabilities that exist in our digital landscape and the ethical quandaries faced by organisations when their data security is compromised. Ultimately, the choices made today will shape the future of cybercrime and the measures needed to safeguard sensitive information in an increasingly interconnected world.

Share This Article
Alex Turner has covered the technology industry for over a decade, specializing in artificial intelligence, cybersecurity, and Big Tech regulation. A former software engineer turned journalist, he brings technical depth to his reporting and has broken major stories on data privacy and platform accountability. His work has been cited by parliamentary committees and featured in documentaries on digital rights.
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 The Update Desk. All rights reserved.
Terms of Service Privacy Policy