Canvas parent company Instructure reaches 'agreement' with attackers, data breach incident temporarily concluded
EdTech company Instructure reached an 'agreement' with threat actors on Monday following two cyber intrusions into its Canvas learning management system. The company stated that stolen data has been returned and digital destruction confirmed, but cybersecurity experts caution that paying a ransom does not ensure data is completely erased. Meanwhile, multiple class-action lawsuits have been filed, and industry organizations are calling for strengthened federal and state-level cybersecurity support for education.

Education technology company Instructure said Monday it has reached an "agreement" with an unnamed threat actor, days after its Canvas learning management system was breached by cybercriminals twice in less than two weeks.
The second cybersecurity incident, which occurred last Thursday, caused widespread service outages at colleges and K-12 schools across the country. The cybercrime group ShinyHunters posted a message on some users' Canvas platforms at the time, stating that colleges could negotiate a solution with the group by Tuesday—a deadline that matched the one Instructure received.
Cybersecurity experts believe Instructure's "agreement" is suspected to be a ransom payment, a practice strongly opposed by the U.S. Federal Bureau of Investigation (FBI).
Instructure said that as part of the agreement with the unnamed threat actor, the stolen data has been returned to the company, and it has received digital destruction confirmation in the form of a "shred log." Instructure stated that the threat actor said it would not extort Instructure's customers as a result of this incident, and individuals affected by the data breach do not need to contact the group.
"While dealing with cybercriminals can never be completely certain, we believe it is crucial to take every controllable measure possible to provide customers with additional peace of mind," Instructure said in a statement posted on its website Monday.
No 'Guarantee' of Data Deletion
Rebecca Moody, head of data research at Comparitech, a website that reviews cybersecurity and online privacy products, confirmed in a statement Tuesday that ShinyHunters was behind the Canvas cyberattack, and the group had posted information about the first breach on its leak site on May 3.
According to Moody, ShinyHunters claimed in its May 3 post to have stolen 3.65 terabytes of data from approximately 275 million users across 9,000 institutions worldwide. Instructure has not confirmed how many colleges or users were affected by the recent data breaches.
"The post, along with ShinyHunters' individual threats to schools, likely forced Instructure to meet the ransom demand in an attempt to prevent data from being leaked," Moody said. "However, we should not forget that ShinyHunters are cybercriminals. Even if the ransom is paid, Instructure has no guarantee that the data will be deleted."
Currently, multiple class-action lawsuits have been filed against Instructure in federal district courts related to this data breach.
Instructure confirmed last week that hackers illegally accessed its systems on April 29 and May 7 through its "Teacher Free" platform. Instructure said the leaked data includes usernames, email addresses, course names, enrollment information, and messages. The company added that "core learning data (course content, submissions, credentials) was not compromised," and Canvas is now fully operational and safe to use.
Michael Klein, senior director of emergency preparedness and response at the Security and Technology Institute, said that in most cases he agrees with the FBI's view that organizations should not pay ransoms to cybercriminals after a data breach, but sometimes there are special circumstances—such as when hospitals are hit by ransomware attacks and leaked data could cause physical harm. In such cases, paying the ransom may be necessary, he said.
However, in the case of Instructure, Klein believes the reportedly leaked data does not fall into a scenario requiring ransom payment.
"Moreover, you cannot trust a cybercrime group to keep its promise not to extort all downstream parties involved," Klein said.
The Need for Federal and State Support
When PowerSchool was hacked in December 2024, Klein was serving as a senior cybersecurity advisor at the U.S. Department of Education. At that time, he was able to convene 41 states and Guam within days to share information about the incident, including how to understand the challenges, communicate with the company, and mitigate impacts on schools.
Klein said that in the face of the latest cyberattack on Instructure, such federal-level authority and coordination mechanisms no longer exist. In his personal capacity at the Security and Technology Institute, Klein was only able to convene 22 states last Friday for a similar discussion about the "widespread and understandable panic" caused by Thursday's incident, which disrupted systems at many schools and universities.
Klein noted that when the Department of Education convened states during the PowerSchool incident a year and a half ago, such protected meetings were achieved through the Critical Infrastructure Partnership Advisory Council. However, more than a year ago, the U.S. Department of Homeland Security terminated the council's authorization.
Klein said the Secretary of Homeland Security could restore that authorization without going through Congress, after which the federal government could immediately organize similar convening meetings again.
Klein added that restoring funding for the Multi-State Information Sharing and Analysis Center (MS-ISAC) could provide school districts and state education agencies with as much free cybersecurity threat information as possible.
"This incident, along with the PowerSchool incident, demonstrates that federal and state support is crucial to helping institutions that cannot do this work on their own build capacity," Klein said.
Meanwhile, on Tuesday, the Software & Information Industry Association (SIIA) sent a letter to lawmakers in both chambers of Congress, calling for $36 million in the fiscal year 2027 budget to ensure schools can access digital security services.
SIIA called for $20 million to fund MS-ISAC and $10 million for the "School Emergency Preparedness and Emergency Management Technical Assistance Center" to rebuild a central hub for school-specific cyber incident management. The association also urged an additional $6 million to support the Department of Education in its lead agency role in coordinating education cybersecurity.
"Following 2025 federal funding adjustments that left school districts 'removed' from critical threat monitoring services and key technical assistance centers closed, the U.S. K-12 education sector is currently in its most vulnerable state in a decade," SIIA said in a letter to leaders of the Senate Appropriations Subcommittee on Labor, Health and Human Services, Education, and Related Agencies.