The debate over digital security in education has grown stronger after Instructure, the company behind the widely used Canvas learning platform, reached an agreement with hackers following a major cyberattack that disrupted thousands of universities and colleges worldwide.
The incident has raised fresh concerns about how secure large education systems are, especially those that handle sensitive student information such as exam records, answer sheets and cloud-based academic data. The breach has also brought attention to the risks faced by major education technology platforms used by schools, colleges and universities on a large scale.
Instructure, which operates Canvas LMS, confirmed that it reached an agreement with the hackers behind an April cyberattack. The attack reportedly affected around 9,000 institutions across the United States, Canada, Australia and the United Kingdom.
Reports said the breach caused major disruption, including problems during exams after the Canvas platform went offline. The attackers claimed they had stolen nearly 3.5 terabytes of student and institutional data and threatened to publish it online unless a ransom was paid.
According to reports, Instructure said the hackers claimed they had deleted the stolen data and promised that customers would not face further extortion under the agreement. The company has not confirmed whether any payment was made, though cybersecurity experts often link such agreements to ransom negotiations carried out through encrypted channels.
Instructure said the agreement included confirmation that the data had been returned, digital verification of its deletion and assurances that affected customers would not be targeted again.
The breach was discovered on April 29 and was claimed by the ShinyHunters extortion group, which has been linked to several major cyber incidents in the past.
Canvas LMS was affected by both a data breach and service outage. Instructure said it was investigating a cybersecurity incident involving some user data, including names, email addresses, student ID numbers and messages exchanged between users.
The company added that it had found no evidence that passwords, dates of birth, government identification numbers or financial information were accessed in the breach.





