Theme:
Light Dark Auto
GeneralTop StoriesPoliticsBusinessEconomyTechnologyInternationalEnvironmentScienceSportsHealthEducationEntertainmentLifestyleCultureCrime & LawTravel & TourismFood & RecipesFact CheckReligion
CRIME & LAW
Negative Sentiment

Instructure向ShinyHunters黑客支付巨额赎金

Read, Watch or Listen

Instructure向ShinyHunters黑客支付巨额赎金
Media Bias Meter
Sources: 2
Center 100%
Sources: 2

United States-based Instructure, the developer of the widely used Canvas learning management system, has confirmed it paid a ransom to the cyber-extortion group ShinyHunters after a massive breach affecting education institutions worldwide. The company said it transferred the payment one day before a final deadline of May 12, 2026, following the theft of 3.6 terabytes of data linked to roughly 275 million users at more than 8,800 institutions, including major U.S. universities and K-12 school districts. Stolen information included student and staff names, email addresses, ID numbers and billions of private messages exchanged on the platform. The attackers escalated the incident on May 8 by defacing login portals at about 330 institutions, blocking access for students and faculty during critical final examination periods. United States investigators found that the hackers exploited a vulnerability in Canvas’s “Free-For-Teacher” account feature to bypass security boundaries and reach institutional data, prompting Instructure to disable that feature and deploy additional security patches. Chief executive Steve Daly said the company received digital confirmation of data destruction in the form of “shred logs” and assurances from ShinyHunters that it would not further extort Instructure’s customers, although the firm did not disclose the size of the ransom. The Federal Bureau of Investigation generally advises against paying ransoms, but Instructure said it proceeded with the settlement because of the immediate risks to student privacy and the disruption to academic operations during exams.

Prepared by Emily Rhodes and reviewed by editorial team.

Timeline of Events

  • 2026年初,黑客利用“免费教师”漏洞
  • 2026年初,攻击者访问了Canvas机构数据
  • 2026年5月8日,330所机构的登录门户被篡改
  • 2026年5月8日,学生和教职员工在考试期间被阻止
  • 2026年5月11日,Instructure支付了ShinyHunters的赎金要求
  • 2026年5月11日,公司收到了数字销毁日志确认
  • 2026年5月12日,设定了最终赎金支付截止日期
  • 2026年5月中旬,Instructure应用补丁,禁用该功能

Why This Matters to You

如果您是受影响的 2.75 亿用户之一,您的数据可能会面临风险。请检查您的学校是否使用 Canvas,并立即更改密码。警惕可能是网络钓鱼诈骗的可疑电子邮件。

The Bottom Line

这次数据泄露事件凸显了在数字时代,尤其是在教育领域,网络安全至关重要。Instructure 决定支付赎金,尽管有争议,但旨在保护学生隐私和学术运营。如果认识教育行业的人,值得转发。

Media Bias
Articles Published:
1
Right Leaning:
0
Left Leaning:
0
Neutral:
1

Who Benefited

源中未指定。

Who Impacted

未在源中指定。

Media Bias
Articles Published:
1
Right Leaning:
0
Left Leaning:
0
Neutral:
1
Distribution:
Left 0%, Center 100%, Right 0%
Who Benefited

源中未指定。

Who Impacted

未在源中指定。

Coverage of Story:

From Left

No left-leaning sources found for this story.

From Center

Instructure向ShinyHunters黑客支付巨额赎金

JQJO
From Right

No right-leaning sources found for this story.

Related News

Comments

JQJO App
Get JQJO App
Read news faster on our app
GET