Education platform Canvas confirmed it reached a settlement with hackers following a major ransomware attack that compromised hundreds of millions of student records and caused widespread service disruptions.
Instructure, the US firm operating Canvas, disclosed the agreement after a week of outages affected schools globally. The attack resulted in stolen data, delayed assignment deadlines, and defaced login pages.
The ransom decision highlights a recurring dilemma for companies facing data breaches. While cybersecurity experts and government agencies consistently advise against paying attackers—arguing it funds criminal operations and encourages future attacks—many organizations proceed anyway to mitigate privacy risks and restore operations quickly.
Once ransoms are paid, questions persist about stolen data. Cybercriminals often claim to delete information but provide no verification. Some data inevitably circulates on dark web marketplaces or leaks publicly despite payment.
Canvas users now face uncertainty about whether their information remains secure. Instructure has not disclosed specific details about the settlement or confirmed data deletion.
The incident underscores the growing threat to education infrastructure and the difficult calculus institutions face when balancing ransom demands against operational and reputational costs.
A new Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service attacks and root-level privilege escalation.
The FBI has dismantled proxy tools used by Chinese hackers in a widespread campaign against NASA, the Federal Reserve, the US Senate, and the Justice Department. The operation marks a significant coordinated response to months of intrusions into critical US infrastructure.
Snowflake is phasing out password authentication for legacy service accounts, requiring organizations to adopt passwordless methods. The real challenge: identifying which accounts exist, who manages them, and what access they hold.
Medical technology company Boston Scientific disclosed a cyberattack that disrupted IT systems and operations worldwide. The company is working to restore normal services.