Overview
- Instructure said it reached an agreement with the ShinyHunters hackers and received confirmation that stolen Canvas data were returned and destroyed.
- The company did not disclose whether it paid a ransom, and no independent proof has been shared that the data are truly gone.
- Dutch schools started moving back to Canvas after local checks, with Tilburg University and Fontys switching service back on while TU/e and Summa held off for more certainty.
- The breach exposed names, email addresses, and student or staff numbers, and it kept many students from seeing grades or turning in assignments while systems were offline.
- Instructure apologized, said the agreement covers all affected customers, and noted that universities were not contacted by the hackers for payment.