惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
Y
Y Combinator Blog
云风的 BLOG
云风的 BLOG
Microsoft Azure Blog
Microsoft Azure Blog
腾讯CDC
T
The Blog of Author Tim Ferriss
P
Proofpoint News Feed
Hugging Face - Blog
Hugging Face - Blog
博客园_首页
小众软件
小众软件
美团技术团队
Martin Fowler
Martin Fowler
爱范儿
爱范儿
有赞技术团队
有赞技术团队
博客园 - 【当耐特】
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Microsoft Security Blog
Microsoft Security Blog
宝玉的分享
宝玉的分享
J
Java Code Geeks
B
Blog
V
V2EX
Stack Overflow Blog
Stack Overflow Blog
B
Blog RSS Feed
博客园 - Franky

Enterprise – Silicon Republic

EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey Data breaches going unreported, says Irish compliance survey
Canvas parent settles with hacker group that stole user data
Suhasini Srinivasaragavan · 2026-05-12 · via Enterprise – Silicon Republic

Instructure did not say what it had given the hacker group in exchange for the terms.

Instructure, the parent company behind Canvas, the education management platform reportedly hacked by ShinyHunters, has reached an agreement with the cyber gang, it said yesterday (11 May). Hackers had given affected universities until tomorrow (12 May) to negotiate a settlement.

As per the agreement, the cyber extortion group has returned stolen data and deleted copies, and has agreed not to extort the institutions affected in the hack, Instructure said. The company did not say what it had given the hacker group in exchange for the terms.

Reportedly formed around 2020, ShinyHunters has claimed responsibility for an array of high-profile, financially motivated attacks in recent years on organisations such as Salesforce, Allianz Life, SoundCloud, Ticketmaster and Tinder-parent Match Group.

The group was linked to a breach of the European Commission’s Europa.eu platform in March, where 350GB of data, across multiple databases, was reportedly accessed and stolen.

Hackers seemingly began targeting edtech giant Instructure late last month; the company started noticing unauthorised activity in Canvas on 29 April, and later on 7 May.

ShinyHunters claimed responsibility for the attacks and said it stole 280m records. The threat actor also published a list of more than 8,800 institutions that were affected by its attacks on Canvas. In a 3 May ransom note, it threatened to leak “several billions of private messages among students and teachers”.

In Ireland, the platform is used by the likes of University of Galway and Munster Technological University – both of which faced disruptions following the hack.

Instructure, at the time, said the stolen information includes user identifying information such as names, email addresses, messages and student ID numbers at affected institutions. It has reported the breach to the FBI, the US Cybersecurity and Infrastructure Security Agency and other law enforcement agencies, it said.

In its latest update, the company said that the unauthorised actor exploited an issue related to its ‘free-for-teacher’ accounts to hack Canvas. As a result, the feature was temporarily shut down; all services, however, are now fully operational, it added.

“ShinyHunters timed this attack to sting as much as possible,” said Raluca Saceanu, the CEO of Smarttech247.

“With exam season underway and academic years drawing to a close, schools and universities needed Canvas working. That dependency gave ShinyHunters the leverage to lay out the terms of their deal. For Canvas, and its parent Instructure, it was agree to terms or lose customers.

“While technical recovery time from ransomware attacks is accelerating, attackers are responding by shifting their focus and making the broader organisational consequences more damaging than ever.

“It’s not just a question of causing as much potential damage as possible. From the attackers’ point of view, these newer approaches are faster, cheaper, stealthier and carry lower technical risk. And the core law of extortion anywhere holds – even if a victim pays, there’s no guarantee data won’t be exposed anyway, and the organisation has now marked itself as a valuable target.”

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.