Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

211–220 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#211
post #168

Earlier quoted context omitted.

The obverse is true - because a ransom organization is dependent upon their reputation, a company claiming to have paid and received confirmation from the group could prevent them from releasing it as well. The general public (including the next victims) don't have a way to confirm if payment was made. ShinyHunters would have to choose between arguing publicly that they were not paid or not releasing the data to prot…

Good/funny observation. Game theory and economics are fun. :D I do think that the partial information problem relating to new entrants into this market is interesting though. The number of potential threat actors with partial/no information but that might speculate based on grandiose visions of ransom or outdated history is high. We see dumb attempts at real-world ransoms/extortion which don't get paid at a pretty hi…

It's an interesting idea, although I think in the heat of the moment, the last thing your org should be thinking of will be playing games with one of the most prolific hacker groups on the planet.

You'll probably get your data leaked anyways, potentially get compromised again (see Instructure situation) and end up in a way worse place if you just shut up and paid it, or let it leak normally.

Re: Instructure pays ransom to Canvas hackers

#212

Earlier quoted context omitted.

The name ShinyHunters is currently quite well-known due to a number of high-profile hacks (Odido in the Netherlands this year was huge). Their brand has a significant value right now.

How does everyone know its ShinyHunters and not someone pretending? I imagine they have some mechanism to authenticate, I'm curious what it is.

Because ShinyHunters published they hacked Canvas on their own website. They also redirected the canvas login pages to a ShinyHunters message, whilst this could be done by another group/person, its unlikely.

You can also validate PGP keys and TOX accounts, etc via their website.

Re: Instructure pays ransom to Canvas hackers

#213

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music

Backups were not Instructure’s problem. Hackers using the threat of exposing private information to extort Instructure’s customers was the problem.

Re: Instructure pays ransom to Canvas hackers

#214

Earlier quoted context omitted.

This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music

Backups were not Instructure’s problem. Hackers using the threat of exposing private information to extort Instructure’s customers was the problem.

Equifax and other companies routinely leak customers PII and financial information.

the only outcome I got from their incidents is 1 year free "identity protection service" which I didnt use.

Should be a lesson for Instructure to have proper architecture and do not store PII they dont need in their processes.

Re: Instructure pays ransom to Canvas hackers

#215

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

Paying a ransom should always be illegal with federal criminal charges for the employees who authorize the payment. If businesses are destroyed or people die as a consequence then those are acceptable casualties.

Re: Instructure pays ransom to Canvas hackers

#216
post #102

Earlier quoted context omitted.

Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway. Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual. Grades? Could be a FERPA violation. Critical PII such as SSNs? Probably not in the LMS to begin with.

I just spoke with a K-12 teacher I know, and she confirmed SSNs in the Canvas instance. Yikes.

That is a big yikes, but definitely not the norm. Most school districts switched from using SSN as their SIS identifier decades ago.

Re: Instructure pays ransom to Canvas hackers

#217

I've seen half a dozen comments in this thread suggesting that paying hacking ransoms should be illegal, but I strongly disagree, for multiple reasons. I'll just make this a top-level comment rather than picking one to reply to. (1a) Multiple have suggested that the US made it illegal to pay kidnapping ransoms. This is a misconception. The US adopted a policy that the government itself would not pay ransoms, but expl…

The problem is paying ransom to these groups gives teenagers millions of dollars in crypto to spend on more exploits and more insiders.

It is a race to the bottom. The teenagers have effectively unlimited time, millions of dollars and rocket launchers.

Re: Instructure pays ransom to Canvas hackers

#218

What data held by Instructure is so critical it warrants a ransom payment?

Tons of stuff, usernames, first name, last name, email addresses. - Most of this stuff isn't "private" per se, but its also not publicly index-able for a reason.

Conversations between students, conversations between teachers and other students/staff or teachers. Course content, etc.

Re: Instructure pays ransom to Canvas hackers

#219

> We received digital confirmation of data destruction (shred logs). This is shockingly naive

Hackers have an incentive to destroy the data as promised, because if it becomes a trend where the data is leaked despite the ransom being paid, no one would pay ransoms in the future.

Obviously this doesn't stop hackers from selling the data anyway and say "it wasn't us, someone else got the same data through a different hack".

Re: Instructure pays ransom to Canvas hackers

#220

Earlier quoted context omitted.

How is it not a violation of AML laws to pay a ransom like this? Surely they didn't verify that the recipient (a criminal) isn't sanctioned or associated with sanctioned organizations.

Money laundering is the action of obfuscating the origin of criminal proceeds; victims or clients of criminals do not generally commit money laundering, for example buying drugs is not a form of AML violation regardless of the legality of the purchase itself or the fact that the funds will later be laundered by the traffickers. KYC is a tool to prevent money laundry and it's typically an obligation of financial insti…

I think they mixed up sanctions (and any similar laws w.r.t. legal recipients) with AML laws. The legality of paying sanctioned entities doesn't depend on whether the money was laundered, but they were interested in how people get around the former.
Post reply on HN