Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

1–10 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#3
>The data was returned to us.

It was my understanding that the data was copied[1]. You wouldn't "return" data unless it was encrypted or the originals were deleted. I am confused on this phrasing but maybe it is standard idk.

This is bullish on Monero[2]. The January pump may have been from a hack as well[3].

Here is Shinyhunters website. Canvas was listed on it[4] and then removed[5].

[1] https://www.youtube.com/watch?v=IeTybKL1pM4

[2] https://search.brave.com/search?q=monero+price&rh_type=cc&ra...

[3] https://xcancel.com/zachxbt/status/2012212936735912351

[4] https://archive.ph/4zD7f

[5] https://archive.ph/NYWbJ

Re: Instructure pays ransom to Canvas hackers

#6

>The data was returned to us. It was my understanding that the data was copied[1]. You wouldn't "return" data unless it was encrypted or the originals were deleted. I am confused on this phrasing but maybe it is standard idk. This is bullish on Monero[2]. The January pump may have been from a hack as well[3]. Here is Shinyhunters website. Canvas was listed on it[4] and then removed[5]. [1] https://www.youtube.com/wat…

I guess the incentive is for the hackers to not leak, so they can get away with the next ransom.

Re: Instructure pays ransom to Canvas hackers

#8
post #5

LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"

I thought it was illegal to pay ransom to hackers. I guess it is legal or maybe it isn't very clear? I thought that there were certain conditions that the company had to check together with law enforcement so that at least the ransom money doesn't go to a hacker group that is on a government payments sanctions list.

Also, does anyone know the root cause of the attack? I read a rumor online (but it's not really confirmed anywhere) that it may have had to do with the common pattern of ShinyHunters where they use a vulnerability in a Salesforce Experience Cloud site. What is confirmed for sure is that the vulnterability involved the feature of Canvas called "Free-For-Teacher accounts".

Re: Instructure pays ransom to Canvas hackers

#9
on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great.

on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator be paid (so their data is not leaked) vs. having their data leaked. so paying is the best for current victims (but increases the potential for future victims).

the dynamics/economics around ransomware is fascinating.

Post reply on HN