Hacked Northwestern Vendor Pays Ransom
Is there honor among thieves?
Last week, I reported on the nation-wide Canvas ransomware attack. The attack knocked out my class at Northwestern for 24 hours. Yesterday, the vendor, Instructure, put out a statement on the “agreement” with the hackers.
Instructure reached an agreement with the unauthorized actor involved in this incident. As part of that agreement:
The data was returned to us.
We received digital confirmation of data destruction (shred logs).
We have been informed that no Instructure customers will be extorted as a result of this incident, publicly or otherwise.
This agreement covers all impacted Instructure customers, and there is no need for individual customers to attempt to engage with the unauthorized actor.
I’ve worked in technology for 20 years — “shred logs” are not a thing. I’m aware of no way to guarantee the malicious actor stored one-and-only-one copy of the data and deleted it. When Uber paid a ransom in 2016, they literally sent the Chief Security Officer to Florida to retrieve the data (and then covered it up, resulting in lawsuits). When Lurie Children’s Hospital was subject to a ransomware attack in 2024, they didn’t pay the ransom.
Instructure seems to be following the PowerSchool playbook: pay the ransom, call the cops, hope they catch the offenders, and pray the student data didn’t get dumped onto the dark web. PowerSchool got lucky — the offender was a 20 year old in Massachusetts and it so far the data hasn’t ended up on the dark web.
The Instructure hackers, ShinyHunters, seem a bit more sophisticated and I think it’s fair to wonder how competent Instructure is. After all, on May 2nd, they claimed the hackers were out of the systems (they’ve subsequently removed this from their status page, but it’s on the Wayback Machine).
Update - We are providing an update on the security incident we advised you of yesterday. While our investigation continues alongside our outside forensics experts, at this stage we believe the incident has been contained.
Here are the steps we have taken since we became aware of the incident. We have:
- Revoked privileged credentials and access tokens associated with affected systems
- Deployed patches to enhance system security
- Out of an abundance of caution, we rotated certain keys, even though there is no evidence they were misused
- Implemented increased monitoring across all platforms
While we continue actively investigating, thus far, indications are that the information involved consists of certain identifying information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as messages among users. At this time, we have found no evidence that passwords, dates of birth, government identifiers, or financial information were involved. If that changes, we will notify any impacted institutions.
Thank you for your patience as we work to resolve this matter. We sincerely regret any inconvenience or concern this may cause. We will continue to keep you apprised as our investigation progresses. For up-to-date information on specific systems, please continue to visit our status page.
Steve Proud
Chief Information Security Officer
May 2, 12:46 MDT
Only five days later, ShinyHunters took down the whole site and began the ransomeware attack. It’s entirely possible that ShinyHunters is still in the house. I’m not the only one wondering this, Instructure’s CEO is being called to testify to a Senate Committee. Instructure is not a small startup — Canvas serves nearly 9,000 universities and was bought by private equity firm, KKR for $4.8 billion dollars in 2024.