Lead

The US-based company behind Canvas, one of the world's most widely used educational platforms, has reached an agreement with the hacking group responsible for a massive data breach that compromised personal information of millions of students and staff. The breach, which disrupted classes at thousands of schools, universities, and other educational institutions globally, has raised serious concerns about the security of educational technology.

Coverage Comparison

The story has been covered extensively by international media outlets, with some variations in the details emphasized. Most reports, including those from the BBC, Al Jazeera, and Deutsche Welle, focus on the scale of the breach, the response by Instructure, and the potential consequences for affected institutions and students.

However, there is disagreement among outlets on a key point: whether Instructure paid a ransom to the hackers. According to a BBC World report, Instructure "paid the hackers not to publish stolen data online." Other outlets, including ABC Australia and Deutsche Welle, state that Instructure "reached an agreement" with the hacking group but note that the company did not explicitly confirm that money changed hands. Al Jazeera and Dawn report the hackers' threats but do not state that a payment was made.

Key Claims

Scale of the Breach

According to multiple sources, the breach affected approximately 9,000 schools, universities, and other educational institutions worldwide, including institutions in the United States, Australia, Canada, the United Kingdom, the Netherlands, Sweden, and Hong Kong. The hacking group ShinyHunters claimed responsibility for the attack in a post on its website on May 3.

Data Compromised

Reports indicate that the stolen data included usernames, email addresses, student ID numbers, course names, enrollment information, and private messages between students, teachers, and staff. ABC Australia and Al Jazeera provided these details, noting the sensitivity of the information.

Data Volume Discrepancy

There is some discrepancy in the reported volume of data stolen. Several outlets, including ABC Australia and Al Jazeera, report that ShinyHunters claimed to have stolen 3.5 terabytes of data from approximately 275 million people. In contrast, Dawn and the South China Morning Post report that the group said it had stolen 6.65 terabytes. This discrepancy has not been resolved publicly.

Ransom Demand and Threats

ShinyHunters threatened to release the stolen data if a ransom was not paid, with a deadline of May 12, according to Al Jazeera. The group initially posted a list of about 1,400 schools and districts, inviting them to negotiate directly to prevent publication, as reported by ABC Australia.

Instructure's Response and Agreement

Instructure announced on May 1 that it was investigating a cybersecurity incident, and on May 6, the company said the situation was resolved and Canvas was fully operational. On May 7, Instructure said it had "reached an agreement" with the unauthorized actor, which included the return of the data and digital confirmation of its destruction. The company stated that no customers would be extorted as a result of the incident, and there was no need for individual institutions to engage with the hackers.

However, Instructure did not explicitly confirm whether money was exchanged. A report from BBC World states that the company paid the hackers, but this claim has not been independently verified by other outlets.

Expert Warnings

Cybersecurity experts have warned that paying ransoms may encourage future attacks. Australia's National Cyber Security Coordinator, Lieutenant General Michelle McGuinness, said the government would not recommend paying ransoms because "cybercriminals cannot be trusted." According to ABC Australia, Brisbane-based cybersecurity consultant Luke Irwin noted that while a ransom amount had not been verified, people claiming to have knowledge of the situation estimated it at US$10 million.

Perspectives

Law Enforcement and Government

The FBI said it was aware of the breach and the disruption to the U.S. education system. In Australia, authorities echoed the official stance against paying ransoms.

Students and Institutions

The breach caused significant disruption as students prepared for end-of-year exams and assignments. Student newspapers reported widespread chaos and frustration. The University of Sydney and the University of Alberta were among those affected and worked to restore service.

Cybersecurity Professionals

Experts like Luke Irwin have highlighted the potential long-term consequences of paying ransoms, noting that it could paint the company as a target for future attacks.

Instructure and Hackers

Instructure, through its CEO Steve Daly, apologized for the disruption and emphasized the importance of protecting its community. The company maintained that the agreement was necessary to give customers peace of mind. ShinyHunters, for its part, initially threatened to leak the data but later removed its posts and said it would not comment further on the incident.