Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

111–120 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#111

Earlier quoted context omitted.

There’s a similar dynamic from within the hacker group itself. For the ransom group, it is better for them to be perceived as trustworthy. Pay the ransom and we won’t leak your data. For any individual within the ransom group, they can get a big payout by selling the data.

Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway. Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual. Grades? Could be a FERPA violation. Critical PII such as SSNs? Probably not in the LMS to begin with.

I have trouble imagining that a ransomware group would care about a regulation like FERPA when they've already done something criminal that would more than enough for prosecution if they got caught.

Re: Instructure pays ransom to Canvas hackers

#112

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

This is the way to go.

Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime.

and the executives who failed to carry regular backups obviously should face the music

Re: Instructure pays ransom to Canvas hackers

#113
post #102

Earlier quoted context omitted.

Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway. Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual. Grades? Could be a FERPA violation. Critical PII such as SSNs? Probably not in the LMS to begin with.

I just spoke with a K-12 teacher I know, and she confirmed SSNs in the Canvas instance. Yikes.

Wow. A lot of K-12 students probably don't even know their own SSN off the top of their head, much less understand the impact of having it stored in this way. I can't fathom why it would be necessary for the SSN to be tracked by the school. At most, the school district as a whole might want a record so they could make sure kids are getting schooled but putting that into Canvas doesn't make any sense to me.

Re: Instructure pays ransom to Canvas hackers

#114

I wonder if, longer term, we're better off if a company like this were in some way destroyed as a result of getting hacked and paying a bribe. I think the stakes for getting hacked are far too low, especially at higher levels of management/executive where it's this abstract thing that has concrete time/resource costs.

I've never seen a company blame a data breach as the point where they started going bankrupt.

Customers never migrate on mass after a breach, 7000 underfunded and overworked education institutions are not migrating on mass.

So I feel safe to say there's no lasting impact to a company when a data breach occurs.

This will all be forgotten in a few months.

Re: Instructure pays ransom to Canvas hackers

#116
post #92

Earlier quoted context omitted.

There’s a similar dynamic from within the hacker group itself. For the ransom group, it is better for them to be perceived as trustworthy. Pay the ransom and we won’t leak your data. For any individual within the ransom group, they can get a big payout by selling the data.

> For the ransom group, it is better for them to be perceived as trustworthy. They've already proved themselves to be untrustworthy simply by ransoming you in the first place.

No, they're proven themselves to be malicious. That's not the same thing at all.

Re: Instructure pays ransom to Canvas hackers

#117

Earlier quoted context omitted.

I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering. The calculus for the victims doesn't seem to change much whether the same people are using a "new" name or an old one to hold their systems hostage.

> I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering. It is very meaningful. You seem to equate that "new" = "trust by default", but a new group is distrusted by default. Let's say that for a new group which is unproven t…

Agreed.

This is the same problem that crypto addresses in an unregulated market - it provides attestation and continuity, but not much else.

New actors are untrusted. Trust must be built through small transactions until someone trusts you enough for larger transactions. Survive long enough without major reputational harm and you can even offer to act as an escrow service for parties with less trust.

Re: Instructure pays ransom to Canvas hackers

#118
post #113
post #102

Earlier quoted context omitted.

I just spoke with a K-12 teacher I know, and she confirmed SSNs in the Canvas instance. Yikes.

Wow. A lot of K-12 students probably don't even know their own SSN off the top of their head, much less understand the impact of having it stored in this way. I can't fathom why it would be necessary for the SSN to be tracked by the school. At most, the school district as a whole might want a record so they could make sure kids are getting schooled but putting that into Canvas doesn't make any sense to me.

Agreed, seems wild to me that anyone in 2026 is using SSN as an identifier in a system that's not doing some kind of tax reporting. It's kryptonite for any other purpose.

Re: Instructure pays ransom to Canvas hackers

#119
I've seen half a dozen comments in this thread suggesting that paying hacking ransoms should be illegal, but I strongly disagree, for multiple reasons. I'll just make this a top-level comment rather than picking one to reply to.

(1a) Multiple have suggested that the US made it illegal to pay kidnapping ransoms. This is a misconception. The US adopted a policy that the government itself would not pay ransoms, but explicitly noted this did not apply to the victims. "The U.S. Department of Justice does not intend to add to families’ pain in such cases by suggesting that they could face criminal prosecution."

(1b) Despite this policy, the US pays ransoms anyways. Usually in the form of prisoner swaps, but in 2023 it released $6 billion in frozen Iranian funds in exchange for the release of 5 hostages[1].

(2) The belief that paying ransoms should be illegal is predicated on the belief that criminals will be less likely to commit the crime if there is no money to be made. This may be true for kidnapping, but that does not mean it would be true for hacking. Kidnapping is a high-stakes, high-commitment crime that requires physical presence and exposes the criminal to significant danger. If the criminal anticipates no reward, the risk-reward calculus skews them away from kidnapping. However, hacking is a low-risk crime. Even if the chance of reward is low, the risk is also low, so hackers are unlikely to be deterred from hacking. Many hackers will do it just for fun or to prove that they can. Moreover, hackers can profit in other ways, for example by selling the data on the black market, or by making use of the data themselves as a nation-state or corporate espionage actor. Hacking will undoubtedly continue as long as things can be hacked, regardless of whether ransoms are ilegal.

(3) Making ransoms illegal pushes the burden onto people who have no real ability to do anything about it. When a company fails to pay ransom, it is the customers who suffer. It does not materially affect the company in any way to have customer data leaked. The market has already shown, overwhelmingly, that it will not punish companies that leak user data. That a company pays a ransom to begin with indicates that they don't actually understand the market and/or have some small shred of a conscience. Rather than making it illegal to pay ransoms, I would rather see penalties for having a data breach in the first place, but once a data breach is assured, companies should be paying ransoms to try to mitigate the damage to their customers.

(4) The idea of trying to solve hacking by making it illegal to pay ransoms is ridiculous on its face. As long as systems are insecure, hackers will exist, so the legal emphasis should be on consequences for data security. The collection of PII that is not essential to providing a service to customers should be discouraged, and there should be real consequences for negligent security. There should be an investigative board similar to those for airline crashes and infrastructure collapse, which examines the circumstances in depth and identifies whether the company is at fault for negligent handling of PII.

[1]https://2021-2025.state.gov/briefings/department-press-brief...

Re: Instructure pays ransom to Canvas hackers

#120

Being that this is HN, do we know how they got hacked? Can we learn something about protecting our services?

I read online that it has to do with their "Free-For-Teachers accounts" which I assume is a way for teachers to get access to Canvas services for free when their school doesn't subscribe to it.

I don't know for sure, but I think it probably had to do with some kind of misconfiguration on an Salesforce Experience Cloud site. I have heard that ShinyHunters often exploits this type of service and that it is very easy for companies to forget to set the right permissions to data and they end up throwing a bunch of different data into Salesforce.

Post reply on HN