Edtech Company Instructure Reveals Data Breach Following Ransom Demands
Data Breach at Instructure Exposes Sensitive Information
Instructure, a leading education technology company, has disclosed a recent data breach caused by a cyberattack that disrupted services and exposed sensitive user information.
Immediate Response and Containment Measures
Upon discovering the breach, Instructure swiftly mobilized its team to contain the incident. The company announced that it had retained external forensics experts to investigate the matter and was working closely with them to determine the full extent of the breach.
- Revoking privileged credentials and access tokens
- Deploying security fixes
- Implementing enhanced monitoring
- Issuing new application keys, requiring users to reauthenticate access to tools
ShinyHunters Extortion Group Claims Data Theft
The notorious ShinyHunters extortion group added Instructure to their leak site on May 3, claiming the theft of 3.65 terabytes of data. The threat actor alleged that the stolen information belonged to 275 million students, teachers, and other individuals at nearly 9,000 education institutions worldwide.
Ongoing Investigation and Security Measures
Security teams and researchers continue to analyze the situation, providing updates on the ongoing investigation and potential implications for the affected parties. As the situation unfolds, stakeholders are advised to remain vigilant and monitor official announcements from Instructure for further guidance.
