惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
A
About on SuperTechFans
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog RSS Feed
U
Unit 42
Stack Overflow Blog
Stack Overflow Blog
Recent Announcements
Recent Announcements
雷峰网
雷峰网
罗磊的独立博客
Microsoft Security Blog
Microsoft Security Blog
Hugging Face - Blog
Hugging Face - Blog
L
LangChain Blog
人人都是产品经理
人人都是产品经理
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Help Net Security
P
Proofpoint News Feed
The Cloudflare Blog
D
Docker
大猫的无限游戏
大猫的无限游戏

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
FBI warns students and staff that ShinyHunters may come k...
Graham CLULEY · 2026-05-20 · via Consumer Insights

When the FBI puts out a public service announcement that deliberately appears to avoid naming the company at the centre of the story, you can usually work out which one it is...

On 15 May 2026, the FBI's Internet Crime Complaint Center (IC3) issued an advisory about the ShinyHunters extortion gang that recently breached "an online Learning Management System" used by educational institutions across the United States.

The advisory doesn't say the platform that was hacked was Canvas, and that the company concerned was Instructure.

Frankly, it didn't need to. The security breach was not just big news on cybersecurity blogs, it made headlines worldwide.

On 12 May, Instructure quietly confirmed it had reached "an agreement" with the attackers, who apparently had helpfully provided "digital confirmation of data destruction (shred logs)."

In short, Instructure paid the ransom.

There are a few possible problems with paying an extortion gang and trusting that they will honour the deal. One of the big problems is that it requires you to trust an extortion gang.

And I supposed that's why the FBI wrote its PSA. It's a polite reminder to everyone (whether they be students, parents, or staff) that their data may still be out there - and that it might be sensible to be braced to the possibility that criminals could prove not to be trustworthy - and start putting the stolen information to work.

For instance, ShinyHunters or their cybercriminal counterparts could use the potentially sensitive personal information to harras innocent parties caught up in the breach through no fault of their own.

As the FBI warns, in an attempt to extort money ShinyHunters "commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting."

Furthermore, extortionists might falsely claim to have access to compromising information, such as embarrassing photographs or videos of victims.

And then there is always the possibility of spearphishing campaigns, where hackers can disguise their poisoned messages through the use of stolen student IDs, professors' names, or snippets of private messages that were stolen in the breach.

The FBI advises that victims do not engage with anyone claiming to hold their data for ransom, and wait for official guidance from their educational establishment to learn what details may have been compromised.

Furthermore, users are advised to not click on suspicious links or unsolicited attachments, and to enable multi-factor authentication where possible to harden the security of their accounts.

Every successful ransom payment writes a sales pitch for the next attack, and ShinyHunters — already linked to incidents at Ticketmaster, the University of Pennsylvania, Princeton, Harvard, Infinite Campus, and McGraw Hill — will not be stopping any time soon.

For students caught in the middle: assume your data is out there, treat every unexpected message with suspicion, and don't let anyone panic you into paying, clicking, or replying. The criminals are counting on your fear. Don't give it to them.

There is, of course, no certainty that ShinyHunters (or any other criminal) will attempt to exploit the information seized by hackers during the Canvas/Instructure breach - but it would it would be wise to consider the possibility, and ensure that defensive measures are properly adopted.

And that advice also goes to other "online learning management systems" and educational establishments. Having receive a ransom payment for its attack on Canvas, ShinyHunters and other extortion gangs are only likely to be further incentivised to launch similar attacks in future.