惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Blog — PlanetScale
Blog — PlanetScale
博客园 - 司徒正美
Vercel News
Vercel News
F
Fortinet All Blogs
月光博客
月光博客
G
Google Developers Blog
博客园 - Franky
GbyAI
GbyAI
The Cloudflare Blog
I
InfoQ
雷峰网
雷峰网
WordPress大学
WordPress大学
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
T
The Blog of Author Tim Ferriss
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 聂微东
小众软件
小众软件
腾讯CDC
B
Blog
量子位
V
V2EX
S
SegmentFault 最新的问题
Google DeepMind News
Google DeepMind News

Cyber Daily News

Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure OpenAI partners with PwC to assist CFOs with AI agents Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay APRA warns of cyber and governance risk due to lagging AI risk management Op-Ed: Australia’s next budget must treat cyber resilience as essential infrastructure Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers Attackers increasingly turning to trusted security tools to compromise Aussie victims Exclusive: Champion Homes confirms customer data compromised in “cyber event” Australia, Japan commit to partnership to meet cyber security challenges & strengthen cyber defences NSW Treasury cyber incident contained, impact no longer ‘significant’ Report: AI-based data incidents on the rise in Australia WA rental scam surge: Tenants targeted with fake $500 discount trap Aussie Information Commissioner launches Privacy Awareness Week 2026 Unregistered branded text messages to be labelled ‘Unverified’ from 1 July US Federal Reserve outlines AI's influence on the finance sector Exclusive: Major Australian jewellery brand confirms cyber incident Australian government establishes new Cyber Incident Review Board Watch this! Komari server monitor tool abused by hackers Act Now! ACSC warns of active exploitation of cPanel & WHM critical vulnerability Exclusive: Kiwi electrical contractor confirms cyber attack
Op-Ed: To pay, or not to pay… That is the existential ran...
2026-05-19 · via Cyber Daily News

Following the ShinyHunters Instructure hack, the morals of paying a ransom to cyber criminals have been a hot-button issue, but what do you really need to know before considering making that payment?

A lot of organisations are pretty firm about whether or not they would consider paying a ransom to criminals who have locked them out of their data and are threatening to publish data online, but those convictions can change rapidly when a ransomware attack actually happens.

No doubt that is the dilemma that Instructure, the provider of the Canvas educational portal, must have faced when the ShinyHunters extortion group breached its systems and boasted of having access to the data of millions of students and thousands of schools around the world.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

And, faced with operational disruptions and the very real risk of the personal data of millions of minors being shared online, Instructure made one of the hardest decisions a company can make.

While it is not confirmed, Instructure likely paid up. It weighed up the cost, the trustworthiness of the ShinyHunters hackers, and its duty to its stakeholders – not to mention the waves of press the incident was generating – and made its decision.

The entries listing schools and student numbers on ShinyHunters’ leak site went away, and – for now – the risk of a catastrophic, global data breach has been averted.

But has it really?

Pay or leak?

Allison Nixon is the co-founder and chief research officer at US-based threat intelligence firm Unit 221b, and somewhat of a ShinyHunters expert.

She’s been following the group since its days as Scattered Lapsus ShinyHunters, and outlined the group’s tactics in detail in a February blog post that saw her fielding death threats from the hackers and a highly organised harassment campaign.

And, according to a recent social media post, ShinyHunters is once again targeting her over her no-pay stance.

“Reacting to our advice about the downsides of paying the ransom, [ShinyHunters] are encouraging victims to pay. They contacted media outlets to issue 'corrections' that no one believes,” Nixon said.

“They want you to forget past behaviour that caused victims to stop taking them seriously. They are also flooding our email to make it more difficult for journalists to reach us.”

However, despite the ongoing harassment, Nixon still believes that ransomware actors and cyber extortionists simply cannot be trusted.

“The value proposition for paying rests entirely on how much confidence you have that promises will be kept,” Nixon said.

“Immediate lack of harm does not guarantee future lack of harm. ‘Pay or Leak’ groups often keep the data, and re-extortion can happen later, or after the arrest of a group member.”

Nixon’s correct, too. Some actors, posing as legitimate ransomware operators, have been known to simply republish old datasets in the hope of making a second payday out of the one data breach. Hackers know the data they have is valuable, and if a company has paid for it not to be published once, they may well be induced into paying a second ransom at some future date.

And the fact is, criminals are inherently untrustworthy.

“Promises should be understood in the context that most extorters are drug addicts and/or mentally unstable,” Nixon said.

“Ask yourself what matters more to them: their reputation, or more cocaine?”

The other thing that organisations need to consider is that groups like ShinyHunters are experts or forcing their victims to act emotionally, not rationally.

“Be wary of psychological tactics,” Nixon said.

“Spreading fear, rushing you, media pressure, dragging children into it, are all tactics of scammers that don't want you to act rationally.”

Ultimately, Nixon asserts, the question of whether to pay a ransom or not should not be made in the middle of an incident, while negotiations may be ongoing or threat actors are engaging in pressure tactics.

Nixon clearly believes paying a ransom is not a solution, and at best a delaying tactic until the same actor – or a second one – makes another extortion attempt.

However, whether or not you agree with her, she is correct – this is a decision that all organisations need to consider well ahead of any actual incident. It should be an essential part of any incident response playbook, based on a detailed understanding of risk appetites, data held, and the consequences of business disruption.

And the time to make that decision is now.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.

Tags: