Connect with us

Tech

Instructure strikes deal with hackers who breached it twice

Published

on

Instructure, the maker of the popular school information portal Canvas, said on Tuesday it has “reached an agreement” with the hackers who breached its systems twice, stole a huge amount of student and staff data, and disrupted thousands of schools that rely on the company’s software.

ShinyHunters, a financially motivated cybercrime group, took credit for the April 29 data breach, claiming to have stolen student and staff data, including the personal information, of a total 275 million people. The hackers said they had compromised Canvas, which nearly 9,000 schools use to manage their students’ data and coursework.

The hackers last week breached the company for a second time, defacing the Canvas login pages on school websites, as part of efforts to pressure the company into paying their ransom.

Instructure said on its incident page late on Monday that as part of the agreement, the hackers had provided evidence that the stolen data was destroyed, and that Canvas customers would not be extorted. 

The company acknowledged that there is “never complete certainty” when negotiating with cybercriminals, but noted that customers should not have to engage with the hackers.

Financial terms of the agreement were not disclosed, and Instructure did not say how much it paid the hackers. Instructure spokesperson Brian Watkins did not respond to a request for comment, or answer questions about the agreement when contacted on Tuesday.

In a post on its leak site, which TechCrunch has seen, ShinyHunters was threatening to publish the stolen data it stole from Instructure if the company did not pay their extortion demand. 

As of Tuesday, the listing had been removed from the ShinyHunters’ page, indicating that a ransom may have been paid.

A representative from ShinyHunters told TechCrunch: “The data is deleted, gone. The company and it’s [sic] customers will not further be targeted or contacted for payment by us.”

It’s not clear why Instructure paid the hackers. Governments, including the United States, have long urged victims of cybercrime not to pay ransoms to hackers, as this helps cybercriminals profit from their attacks. Security researchers have argued that victims cannot trust the word of malicious hackers — some cybercriminals have been found holding on to stolen data despite saying they had deleted it so they could continue extorting their victims.

The hack on Instructure mirrors a cyberattack on PowerSchool, which was hit by a massive data breach affecting 70 million students and staff in 2024. PowerSchool, which also makes school information software, paid the hackers to return the stolen data, but several of its customers were later extorted by another crime group that showed data from the breach that had not been destroyed.

The FBI said in a statement last week that it was “aware” of the system disruption affecting schools and educational institutions around the United States. The notice did not name Canvas, but it did mention that victims should “not send payment or respond” to the demands of cybercriminals.

The data stolen from Instructure, some of which TechCrunch has seen, includes students’ names, their personal email addresses, and messages exchanged by teachers and students, including private and personal information.

On its website, Instructure acknowledged that hackers had breached the company’s systems twice in under a year, but said that the two breaches were “distinct events” that involved different systems. 

Instructure said it was still investigating the breach and validating its findings.

It’s not clear who at Instructure oversees or is responsible for cybersecurity, if not the company’s chief executive, Steve Daly. When contacted by TechCrunch, Instructure would not say if Daly plans to resign following the data breaches.

Are you a Canvas administrator or school notified about the breach? Have you received an extortion demand from the hackers? We want to hear from you. To contact this reporter securely, reach out via Signal username zackwhittaker.1337.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Google Workspace Lets Admins Set Role Expiration Dates

Published

on

Google Workspace now lets admins time-limit role assignments for users, security groups, and service accounts. See how expiration works and its key limits.

The post Google Workspace Lets Admins Set Role Expiration Dates appeared first on TechRepublic.

>

Continue Reading

Tech

a16z-backed EliseAI raises $350M, doubles valuation to $4B

Published

on

AI startup EliseAI announced on Tuesday that it has raised $350 million at a $4 billion valuation, double what it was worth when it raised its Series E last August.

This latest round was co-led by Andreessen Horowitz and Bessemer Ventures. EliseAI, founded in 2017, automates administrative and operational work for housing and healthcare companies. It said its software is used by 1 in 6 apartments across the country and announced this summer it passed $200 million in ARR. 

Earlier this month, Elise announced the launch of an AI “teammate” called Apollo that helps with tasks inside the EliseAI platform. “It’s built natively into the same platform that already runs leasing, maintenance, and renewals,” co-founder and CEO Minna Song told TechCrunch. “So it can act across every role on a property team.” 

EliseAI also helps automate the patient-related paperwork for specialty physician groups on the healthcare side, “from the first inbound call through referrals, scheduling, insurance verification, chart prep, and follow-up, so nothing falls through the cracks,” she said. The company has targeted housing and healthcare because they are two of the “largest expenses for American households,” she said.

>

Continue Reading

Tech

Excel Breaks a 40-Year Rule: Microsoft Lets One Cell Hold Multiple Values

Published

on

Microsoft is changing a 40-year-old Excel rule by allowing a single cell to hold multiple values using new lists, arrays in cells, and nested arrays.

The post Excel Breaks a 40-Year Rule: Microsoft Lets One Cell Hold Multiple Values appeared first on TechRepublic.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.