Instructure, the parent company of the Canvas learning management system, says it has reached an “agreement” with ShinyHunters, a hacking and extortion group, following a ransomware-linked breach. Multiple outlets report that ShinyHunters claimed responsibility for the attack and threatened to leak large volumes of stolen student and institutional data if victims did not comply. Instructure said it reached an agreement to prevent the data from being published online, and that Canvas “remains safe to use,” while noting the company experienced disruptions during the incident. Reports describe data theft on the order of several terabytes and include claims from ShinyHunters that the leaked information could affect very large numbers of individuals. Some coverage and security experts interpret Instructure’s wording as potentially indicating that payments may have been involved, but Instructure does not disclose the terms publicly. Separately, at least one outlet reports ShinyHunters escalated the extortion campaign by targeting multiple schools, including defacing login pages, as negotiations proceeded. Instructure also previously indicated it apologized for the incident and worked to restore services.