Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

201–210 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#201

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music

The criminals have better marketing than the disaster recovery vendors.

Re: Instructure pays ransom to Canvas hackers

#202

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Who would of thought paying teenagers millions of dollars in crypto was a good idea? They'll just use it on more exploits, more nonsense. It's a race to the bottom. Sister group, Lapsus$ (parent group ShinyHunters) has published on their website they will pay for inside access to company networks. The group says they don't want data, they just want an avenue. This is what happens when we keep paying these criminals m…

I suppose it also puts a price on not funding your security department.

Re: Instructure pays ransom to Canvas hackers

#203

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Isn't there still incentive because the data itself is valuable so attacks would continue?

If there was a way to profit from the data that was more than the ransom, wouldn't they just do that instead of asking for a ransome.

Or do both i suppose, just because someone pays a ransome there is no garuntee the hacker destroys the data.

Re: Instructure pays ransom to Canvas hackers

#204

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music

If they can restore from backups, then there’s no need to pay the ransom in the first place… Ransomware is designed to silently corrupt your backups.

Re: Instructure pays ransom to Canvas hackers

#205
post #128

Being that this is HN, do we know how they got hacked? Can we learn something about protecting our services?

This blog post[0] suggests that, based on their changelog after the incident, the hackers may have extracted session tokens using XSS in a support ticket. Then the ransom note was displayed using a custom theme. [0]: https://cyber.acmucsd.com/canvas (disclosure: I was involved with this org when I was a student)

Surely if they are demanding a ransome they somehow got server access to delete data. Would seem kind of insane to pay a ransome solely for an XSS.

Re: Instructure pays ransom to Canvas hackers

#206

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

[dead]

Re: Instructure pays ransom to Canvas hackers

#207
post #88

Earlier quoted context omitted.

And that’s exactly why the incidence of kidnapping plummeted in Italy once ransom payments were made illegal

How does that work? I.e. say a kidnapping occurs and the ransom is paid. What kind of trouble does the paying party get into? A fine? Jail?

A fine or sentence is probably on the books but it never comes to that. The main thing is to freeze the family's assets, and more importantly to publicize this procedure so the mafia or whoever knows there's no point in threatening the family.

Re: Instructure pays ransom to Canvas hackers

#208

Earlier quoted context omitted.

There’s a similar dynamic from within the hacker group itself. For the ransom group, it is better for them to be perceived as trustworthy. Pay the ransom and we won’t leak your data. For any individual within the ransom group, they can get a big payout by selling the data.

I don’t know if that’s really true. Nobody would really give a shit if you leaked where everyone goes to college… because it’s already on their LinkedIn or whatever. The only people it’s valuable for is the ransomee, because they don’t want the reputational hit of having their data everywhere.

It really isn't as simple as that.

You are leaking email addresses that likely otherwise wouldn't be out there publicly. Whilst email addresses and names are "effectively" public, they aren't just in a one big database anyone on the planet can access.

Every single one of those email addresses will receive increased spam and phishing attempts, with more isolated information (such as School, First+Last Name, Subjects, Teachers/Lecturers, etc) the phishing attempts can be more refined.

i.e, Student receives an email that looks like its from their school (has email footer, has student name, has relevant teacher name, subject name, etc), the user is now more likely to click some sketchy link.

These little identifiers add up, especially when cross-references with other leaks. Even more problematic when most of the users wrapped up in a leak like this are under 18 too.

A lot of this stuff could be done previously, although the effort and scale to do so would of been higher/harder.

Re: Instructure pays ransom to Canvas hackers

#209
post #124

Earlier quoted context omitted.

Oh, it's insane and I recoiled when she mentioned that. But it is 100% happening. People do amazingly stupid things with systems, especially when they don't have enough people with the expertise to set them up properly, so they just throw things in there without stopping to think about whether or not it's a good idea.

So, a particular school system decided to add SSN to the student profile? Or Canvas requires it?

I'm guessing that Canvas just sort of lets you put in whatever data you want, and someone evidently decided that putting the student's SSNs in there made sense...

Re: Instructure pays ransom to Canvas hackers

#210

Earlier quoted context omitted.

I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering. The calculus for the victims doesn't seem to change much whether the same people are using a "new" name or an old one to hold their systems hostage.

The name ShinyHunters is currently quite well-known due to a number of high-profile hacks (Odido in the Netherlands this year was huge). Their brand has a significant value right now.

How does everyone know its ShinyHunters and not someone pretending? I imagine they have some mechanism to authenticate, I'm curious what it is.
Post reply on HN