Two months after Instructure made a deal with hackers to salvage troves of stolen user data, the company—which owns the popular learning management system Canvas—has paused the delivery of data related to the breach because of a potential security threat with a third-party delivery platform.

In May, a criminal extortion group known as ShinyHunters twice hacked Canvas and claimed that it gained access to the personal identifying information of 275 million people across 9,000 institutions. At the time, the company said the leaked information included names, email addresses, student ID numbers and user messages, but it “found no evidence that passwords, dates of birth, government identifiers, or financial information were involved.”

In the aftermath, Instructure CEO Steve Daly vowed to be “transparent about what happened” and provide K–12 schools and higher education institutions “with information as quickly as we responsibly could.” Over the past two months, Instructure has worked “to conduct a detailed forensic review of the data involved in this incident,” Daly said in a memo last week.

New Push to Fix Calculus Bottleneck

Prof Denied Tenure: Academic Freedom at UT Being Dismantled