Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…
How is it not a violation of AML laws to pay a ransom like this? Surely they didn't verify that the recipient (a criminal) isn't sanctioned or associated with sanctioned organizations.
Instructure pays ransom to Canvas hackers
141–150 of 257 posts
Re: Instructure pays ransom to Canvas hackers
#142Re: Instructure pays ransom to Canvas hackers
#143I've seen half a dozen comments in this thread suggesting that paying hacking ransoms should be illegal, but I strongly disagree, for multiple reasons. I'll just make this a top-level comment rather than picking one to reply to. (1a) Multiple have suggested that the US made it illegal to pay kidnapping ransoms. This is a misconception. The US adopted a policy that the government itself would not pay ransoms, but expl…
Re: Instructure pays ransom to Canvas hackers
#144Earlier quoted context omitted.
If you have to pay, at least try to negotiate 1) a guarantee that the hackers won't just do it again sometime later, and 2) full disclosure / assistance in repairing your vulnerabilities so you have some kind of head start for the future. Outside of politically motivated hackers, this would probably be reasonably successful.
What possible type of guarantee could one ever hope to "negotiate" with someone who has just successfully blackmailed/ransomed/extorted?
It's not a good situation to be in, but still, try to make the best of it.
Re: Instructure pays ransom to Canvas hackers
#145Earlier quoted context omitted.
Wow. A lot of K-12 students probably don't even know their own SSN off the top of their head, much less understand the impact of having it stored in this way. I can't fathom why it would be necessary for the SSN to be tracked by the school. At most, the school district as a whole might want a record so they could make sure kids are getting schooled but putting that into Canvas doesn't make any sense to me.
Oh, it's insane and I recoiled when she mentioned that. But it is 100% happening. People do amazingly stupid things with systems, especially when they don't have enough people with the expertise to set them up properly, so they just throw things in there without stopping to think about whether or not it's a good idea.
Re: Instructure pays ransom to Canvas hackers
#146Earlier quoted context omitted.
How is it not a violation of AML laws to pay a ransom like this? Surely they didn't verify that the recipient (a criminal) isn't sanctioned or associated with sanctioned organizations.
How exactly would this fall into the purview of AML? As far as sanctions go the burden of proof would be on the government to prove the money went to a sanctioned entity and Instructure isn't a bank subject to KYC requirements.
From Claude, maybe it's a little nuanced compared to conservative corporate policies, but doesn't feel very legal: "You can be charged with money laundering (18 USC 1956/1957 in the US, equivalents elsewhere) if you knowingly — or with willful blindness — process proceeds of crime. "I didn't ask" is not a defense if the circumstances were suspicious; deliberately avoiding KYC to preserve deniability is exactly what willful blindness doctrine targets. The recipient doesn't need to be formally sanctioned; the funds just need to be tainted."
Re: Instructure pays ransom to Canvas hackers
#147I'm curious about the open source competition ( https://github.com/moodle/moodle is my first find, there are likely others) and what they could've made happen with that money if they had received it instead as an investment re: not worrying about future ransomware attacks.
Re: Instructure pays ransom to Canvas hackers
#148Earlier quoted context omitted.
The customer data is already leaked, unless your threat model somehow includes trusting threat actors to keep said data confidential in perpetuity.
ShinyHunters has a vested financial stake in not leaking the customer data. If they did, nobody would ever pay a ransom to them again. I trust ShinyHunters to look out for themselves continuing to get paid.
Re: Instructure pays ransom to Canvas hackers
#149Earlier quoted context omitted.
Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway. Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual. Grades? Could be a FERPA violation. Critical PII such as SSNs? Probably not in the LMS to begin with.
I have trouble imagining that a ransomware group would care about a regulation like FERPA when they've already done something criminal that would more than enough for prosecution if they got caught.
Re: Instructure pays ransom to Canvas hackers
#150Given they were hacked multiple times, couldn’t they just be targeted again by the same or different group? Why would it stop here?
This is of course assuming that Instructure continues to be relevant, and that students still believe that college education holds economic or social value.