Instructure Strikes Deal to Delete Stolen Canvas Data

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Instructure announced a secret deal with the hacker group ShinyHunters that breached its Canvas platform, agreeing to return stolen user data and destroy copies, while not revealing the exact terms.
- Canvas users, including roughly 230 million students, teachers, and staff, were affected by the breach, which occurred in two separate incidents.
- Instructure confirmed that the stolen data had been returned and that the hackers had deleted the copies, though the company did not disclose what it provided in exchange.
- Congress opened an investigation into the Canvas breach, scrutinizing Instructure’s response and the undisclosed agreement.
- Instructure temporarily disabled its “Free‑For‑Teacher” accounts after attackers exploited that pathway to gain access.
- Media outlets such as The New York Times, TechCrunch, and The Verge consistently framed the settlement as a ransom‑like agreement, emphasizing the secrecy of the terms.
Why it matters: Students, teachers, and schools regain access to their Canvas data, while the undisclosed terms of the deal highlight a lack of transparency in handling ransomware incidents, prompting congressional scrutiny and raising concerns about the precedent set by private settlements broadly.


