Instructure, Canvas’s parent company, reached an agreement with the hackers who put student and teacher data at risk around the world, while acknowledging "there is never complete certainty when dealing with cyber criminals." 

The company said it received digital confirmation that the hackers destroyed the leaked data and that no customers will be extorted again.

Other WRAL Top Stories

“This agreement covers all impacted Instructure customers, and there is no need for individual customers to attempt to engage with the unauthorized actor,” Instructure wrote on its website.

WRAL Investigates asked Instructure twice if it paid a ransom. We also asked how the company knows the hackers do not have copies of the data. An Instructure spokesperson directed us to its status updates page, which did not provide answers to our questions.

Cybersecurity expert Doug Levin said he believes hackers may have started negotiations with Instructure when Canvas was restored last week.

“Actually, the threat actor had removed their extortion demands from their dark web leak site. At that time, our strong suspicion was that there were negotiations happening, or even a payment,” he said.

The deal was announced just hours before the hackers’ supposed May 12 deadline and doesn't share specifics about what Instructure traded.

“You can't trust that they're going to delete the data,” cybersecurity investigator Allison Nixon previously told WRAL Investigates. “There [are] a number of instances in the past where similar activity has resulted in payment and then the data not being deleted. These actors that are behind this are [often] unprofessional kids themselves.”

Nixon said she generally advises against paying a ransom.

“While there is never complete certainty when dealing with cyber criminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible,” the website reads.

Levin said victims caught in ransomware attacks are caught between a “rock and a hard place.”

“I will say, this particular threat actor in the past has successfully extorted customers, and that has, at least so far as we know, kept that data from being further abused. Now, there's nothing to say that this time won't be different, or that others won't try to take advantage of the situation to scam those who were affected. It's also possible, of course, that we could see copycat attacks,” he said.

Levin said companies – especially those as large as Instructure – have to reduce harm as much as possible.

“There is a compelling argument that to reduce further harm, you want to do what you can to keep that information from spreading more widely and getting abused. So, that's what the company did,” he said.

The hack disrupted classes just as the school year winds down – impacting finals at some universities and forcing students to complete assignments with pen and paper.

After briefly shutting down the app to investigate, Canvas came back online late last week. Despite that, Durham Public Schools is still not allowing students and teachers to access Canvas.

Monday evening, the North Carolina Department of Public Instruction restored access to the platform, along with multiple school districts – including Wake County and Chapel Hill-Carrboro schools.

Instructure said the hackers gained access to names, email addresses, student IDs and messages.

The hackers claim to be the ShinyHunters, known for breaching major companies like Microsoft, AT&T and Pizza Hut. However, Nixon told WRAL Investigates it’s common in hacking scenarios that someone will take credit for an attack under another hacker’s name. The goal is to capitalize on one group's notoriety.

“They want to be famous. They want to be remembered,” she said.

This is the second breach of its kind within about a year and a half.

Last year, education-technology company PowerSchool paid a ransom to a hacker. Months later, public school employees across North Carolina received threatening messages from people who said they had access to student and teacher data that was exposed during the PowerSchool hack. Authorities later arrested a college student for the cyberattack.

Instructure said it’s continuing to work with “expert vendors to support our forensic analysis, further harden our environment, and conduct a comprehensive review of the data involved.”

The company is working with CrowdStrike to investigate the breach. Additionally, the chairman of the U.S. House Committee on Homeland Security is calling for the company to provide a public update on the full scope of the breach.