In a dramatic episode highlighting the ongoing battle against cybercrime, Instructure, the tech firm behind the popular educational platform Canvas, has navigated a tumultuous ransomware attack that has left hundreds of millions of students’ data vulnerable. Following a week of chaos that saw login pages defaced and assignment deadlines extended, the company has reportedly reached an agreement with the hackers. While the details remain murky, experts speculate that a ransom may have been paid. As organisations grapple with the decision to pay ransoms, the risks and ethical implications continue to mount.
Instructure’s Ordeal: The Attack Unveiled
The hacking group known as ShinyHunters has claimed responsibility for breaching Instructure’s security, threatening to leak a staggering 3.6 terabytes of sensitive data. This trove includes personal details from 9,000 educational institutions, impacting approximately 275 million students and staff globally. The attack disrupted operations across numerous Australian universities and schools, leading to assignment extensions as students were locked out of their portals.
Instructure has confirmed that the hackers exploited a vulnerability in its Free for Teacher software, allowing them to manipulate login pages, such as that of the University of Texas at San Antonio. The company stated that data had been “returned” to them as part of a deal made with the attackers, alongside documentation confirming