The cybercriminal syndicate expressed deep disappointment Thursday with Instructure’s failure to promptly return their messages regarding the theft of student records.
SALT LAKE CITY — Following a massive breach of the Canvas learning management system, the hacking collective ShinyHunters has publicly reprimanded platform owner Instructure for its severe lack of professional courtesy during an ongoing ransomware negotiation.
The cybercriminal syndicate, which recently acquired comprehensive access to student names, identification numbers, and private messages, stated they were forced to take the Canvas platform offline after Instructure executives repeatedly ignored their demands and instead deployed what the group described as passive-aggressive security patches.
According to a statement posted directly to the Canvas login page, the hackers felt disrespected by the educational tech giant's refusal to engage in a mature, bilateral extortion dialogue.
We reached out through the proper underground channels to resolve this hostage situation amicably, and instead of hopping on a quick call, they just started patching vulnerabilities without telling us. It is incredibly frustrating to put hours of hard work into compromising a global education network only for the vendor to just ghost you.
Forced to bypass Instructure entirely, ShinyHunters has now pivoted to a direct-to-institution extortion model. The group is currently advising individual schools to consult with their cyber advisory firms and contact the hackers directly via the TOX messaging protocol to arrange their own bespoke data suppression packages.
At press time, millions of college students were reportedly attempting to contact ShinyHunters directly to ask if the group’s premium ransomware tiers included permanently deleting their upcoming midterm exams.