The recent Canvas hack has sparked a debate about whether companies should pay ransoms to regain access to their systems and prevent further harm from data release. The US tech firm Instructure, which operates the education platform Canvas, faced a ransomware attack that led to the theft of hundreds of millions of students' data, delayed assignment due dates, and defaced login pages. The hacking group ShinyHunters claimed responsibility and threatened to leak 3.6TB of data unless a ransom was paid.
Instructure announced an agreement with the hackers, but the company has not confirmed whether a ransom was paid. This raises the question of whether firms should pay ransomware attackers to regain access to their systems and potentially prevent further harm from the release of personal information. While governments advise against paying ransoms, many companies ultimately do so.
The debate revolves around the potential consequences of paying ransoms. On one hand, paying ransoms may provide companies with access to their systems and potentially prevent further harm from data release. On the other hand, paying ransoms may fund other criminal activities and ultimately provide no guarantee that the data release will be prevented or that the threats will end.
The decision to pay a ransom is complex and depends on various factors, including the company's risk tolerance, the potential impact of the data release, and the company's ability to recover from the attack. Ultimately, the decision to pay a ransom is a risk-driven position that companies need to work within.
In the case of the Canvas hack, the company's statement was carefully crafted to avoid admitting anything while also demonstrating that an agreement had been reached. The head of cyber at McGrathNicol, Darren Hopkins, notes that ShinyHunters is an extortion group and that the company's statement does not necessarily admit anything but also demonstrates that an agreement has been reached.
The decision to pay a ransom is a complex and controversial issue that requires careful consideration of the potential consequences. While governments advise against paying ransoms, many companies ultimately do so, and the decision to pay a ransom is a risk-driven position that companies need to work within.