Skip to content
The Cyber Security Place

They paid, and received a receipt for a deletion nobody can check

Event dated 28 April 2026 · Published 2 September 2026 · 3 sources

The education platform Instructure was breached twice within about a fortnight by the group ShinyHunters, with initial access in late April 2026 through a free-tier teacher programme, in what has been described as the largest education-sector breach on record. On 11 May, a day before the group's deadline, the company paid and said it had received shred logs said to confirm the data had been destroyed. That document is unverifiable in principle: it is a file produced by the party with every reason to produce it, describing an action that leaves no evidence anywhere the victim can inspect.

Two facts here belong together and are usually reported apart. The first is the payment, which attracts the argument. The second is the interval: breached, remediated, breached again inside two weeks.

The second breach is the more informative one. It says that whatever was done after the first did not close the route, and organisations rarely discover that so quickly. Most learn it months later or not at all, because the same access is used quietly rather than twice in a fortnight.

What a shred log actually is

A file, supplied by the people who took the data, stating that they deleted it. It can be fabricated in a text editor. Even if genuine, it can only describe copies its author knows about, on infrastructure its author controls — not what was passed to an affiliate, sold before the negotiation, or kept by an individual who has since left the group.

That is not cynicism about a particular group. It is the structure of the transaction: deletion is a negative, negatives cannot be demonstrated, and the only party in a position to assert it is the party being paid to assert it.

The document still does work

Not evidential work — institutional work. It goes in the file. It is something to show a board that asked what was obtained for the money, something an insurer's file can record, and something a communications team can refer to without stating a falsehood.

The danger is the slide from that to treating the matter as closed. A shred log tells the people whose records were taken nothing at all, and the correct posture toward those records is unchanged: assume they exist elsewhere and behave accordingly, whatever was filed.

The decision this really tests

Not whether paying is defensible, which depends on circumstances this page cannot see. It is whether the organisation decided in advance what it would accept as evidence that a payment achieved something — because that standard is impossible to set honestly during a negotiation, when the alternative to accepting the offered document is having nothing at all to show.

Boards that have never discussed it will be shown a shred log and asked to be satisfied. The useful version of the conversation happens on an ordinary afternoon, when the answer costs nothing.