In a bid to resolve the turmoil caused by a recent cyberattack, the company behind the Canvas online learning platform has reportedly negotiated with hackers to ensure the deletion of stolen data. This cyber incident wreaked havoc on many students, particularly those in the throes of final exams.
Instructure, the parent company of Canvas, announced through an online statement that it had come to an “agreement with the unauthorized actor involved in this incident.” However, the company remained tight-lipped about the specifics of the agreement, including whether any payment was made, and did not disclose the identity of the hackers.

To address the breach, Instructure temporarily shut down the system, effectively locking out both students and faculty while investigations were underway. This action added to the disruption experienced by countless educational institutions relying on the platform.
Claiming responsibility for the breach was a hacking group known as ShinyHunters. They threatened to leak sensitive data from nearly 9,000 schools worldwide, affecting around 275 million individuals, unless a ransom was paid by May 6. The group later extended this deadline, hinting that negotiations were ongoing with some schools.
ShinyHunters had previously targeted Instructure in a smaller breach last year. In light of these events, a lawsuit filed in federal court in Utah last week accuses Instructure of failing to adequately protect its platform, used by millions of students, thus making it vulnerable to cybercriminals.
As part of the deal, the data was returned to Instructure. The company said Monday that it also received “digital confirmation” that the hackers destroyed any remaining copies, in the form of “shred logs.”
The company acknowledged that there was no way to be sure that the data was erased for good, and said it took action because of concerns about potential publication of the data.
“While there is never complete certainty when dealing with cybercriminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible,” Instructure said.
Cybersecurity experts were skeptical it was the end of the attack. Cynthia Kaiser, a former deputy director of the FBI’s Cyber Division, said the reported deal suggests that a ransom was likely paid.
“What victims must understand is that payment does not end the threat,” Kaiser, now the senior vice president of the Halcyon Ransomware Research Center, said in a written statement. “Stolen data will be used against clients and users for as long as it remains profitable to do so.”
The data breach appeared to involve student ID numbers, email addresses, names and messages on the Canvas platform, Instructure’s chief information security officer, Steve Proud, said earlier this month. The company found no evidence that passwords, dates of birth, government identification or financial information were compromised, it said.
The company said it was working with “expert vendors” to do a forensic analysis, “further harden” its systems, and carry out a “comprehensive review of the data involved.”
The disruption caused panic last week among students and faculty members when they were locked out of a platform they rely on to manage grades and access course notes and assignments.
Schools and universities use Canvas to manage nearly all aspects of instruction. The platform acts as a gradebook, a hub for digital lectures and course materials, a discussion board for classroom projects, and a messaging platform between students and instructors.
Some courses also give quizzes and exams on the platform, or use it as a portal where final projects and papers are submitted on deadline.