FILE PHOTO: Students walk on campus at Columbia University during the first day of the fall semester in New York City, U.S., September 2, 2025. REUTERS/Ryan Murphy/File Photo

Canvas' parent company reaches agreement with hacking group behind recent breach

· CNA · Join

Read a summary of this article on FAST.
Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST Tap here to return to FAST
FAST

May 12 : The hacking group that targeted the Canvas educational tool and the parent company that owns the software struck a deal to secure stolen student and school data, the company said in a statement late Monday.

In a statement posted to its website May 11, the company said it "reached an agreement with the unauthorized actor involved with this incident." As part of the agreement, all data was returned to the company, the company received digital confirmation of data destruction, and the company was informed that "no Instructure customers will be extorted as a result of this incident, publicly or otherwise." 

The agreement covers all impacted Instructure customers, the statement said, "and there is no need for individual customers to attempt to engage with the unauthorized actor." 

A representative for ShinyHunters, the group the claimed responsibility for the breach, said in an online message to Reuters that the "data is deleted, gone. The company and its customers will not further be targeted or contacted for payment by us."

CNA Games

Guess Word
Crack the word, one row at a time

Buzzword
Create words using the given letters

Mini Sudoku
Tiny puzzle, mighty brain teaser

Mini Crossword
Small grid, big challenge

Word Search
Spot as many words as you can
Show More
Show Less

The representative declined to answer specific questions about the agreement. 

Also on May 11, the House Homeland Security Committee sent a letter to Instructure CEO Steve Daly requesting he or another senior company executive brief the committee to address the multiple intrusions claimed by ShinyHunters, questions about the nature and amount of data stolen, what the company has done in response, and "the adequacy of the company's coordination with federal law enforcement and CISA," referring to the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency.

An Instructure spokesperson did not immediately respond to a request for comment on the request for Congressional briefing or the nature of the agreement struck with ShinyHunters. 

Source: Reuters

Newsletter

Week in Review

Subscribe to our Chief Editor’s Week in Review

Our chief editor shares analysis and picks of the week's biggest news every Saturday.

Sign up for our newsletters

Get our pick of top stories and thought-provoking articles in your inbox

Subscribe here

Get the CNA app

Stay updated with notifications for breaking news and our best stories

Download here

Get WhatsApp alerts

Join our channel for the top reads for the day on your preferred chat app

Join here