Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

61–70 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#61

Earlier quoted context omitted.

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

There’s a similar dynamic from within the hacker group itself. For the ransom group, it is better for them to be perceived as trustworthy. Pay the ransom and we won’t leak your data. For any individual within the ransom group, they can get a big payout by selling the data.

Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway.

Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual.

Grades? Could be a FERPA violation.

Critical PII such as SSNs? Probably not in the LMS to begin with.

Re: Instructure pays ransom to Canvas hackers

#62

Earlier quoted context omitted.

Not only is it not illegal, there are insurance policies set up to take care of this very scenario. It's almost always handled by a third party, not the company themselves, that would deal with any such concerns.

It is illegal to pay terrorists. As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If they did, would they be able to send in SEAL Team 6 to handle the hackers?

Iran, Russia and North Korea are the biggest sources of ransomware.

Re: Instructure pays ransom to Canvas hackers

#63

A good infotech public service project would be to maintain a public list of organizations that have succumbed to ransom demands, so that we can choose to take our business elsewhere. It would also be an act of bravery though in the face of potential liability for libel. I doubt disclaimers would evade much of that.

So you would rather take your business to somewhere that got hacked, didn't pay the ransom, and got customer data leaked?

If you believe the hackers didn’t keep a copy of the data, you’re the target market.

Re: Instructure pays ransom to Canvas hackers

#64

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

Another way to view this calculation: if you keep your infrastructure secure and up to date, you (very likely) don't have to pay any ransom in the first place.

Re: Instructure pays ransom to Canvas hackers

#66

Earlier quoted context omitted.

So you would rather take your business to somewhere that got hacked, didn't pay the ransom, and got customer data leaked?

The customer data is already leaked, unless your threat model somehow includes trusting threat actors to keep said data confidential in perpetuity.

ShinyHunters has a vested financial stake in not leaking the customer data. If they did, nobody would ever pay a ransom to them again. I trust ShinyHunters to look out for themselves continuing to get paid.

Re: Instructure pays ransom to Canvas hackers

#67
> Has law enforcement been engaged? Yes. We've notified law enforcement, including the FBI, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and international law enforcement partners.

Hmm. I thought all these agencies say NOT to pay a ransom.

Re: Instructure pays ransom to Canvas hackers

#69

How is Instructure getting away with paying off the ransomware hackers? Is that still legal in Utah or something?

This happens every day, and there doesn't seem to be anything interesting about this case. It's how most situations are resolved. There are money transmitters that specialize in ransoms. They "do" sanctions checks that are about as good as you suspect they are.

Like other commenters have pointed out, it's literally a business. Most trade on reputation, so there actually is an incentive for them to take their money and abide by their agreements. Otherwise, they would have to start from scratch with a fresh identity and rebuild the rep to command their prices.

Re: Instructure pays ransom to Canvas hackers

#70

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

What stops a ransomware group copying all data and just selling it piecemeal on the darknet under posibly a different name?

Realistically, the only people that could check that it's true are buyers, and those benefit from keeping a low profile

Post reply on HN