Weekly Update 504

Troy Hunt News

Summary

Troy Hunt's weekly update discusses the normalization of ransomware payments, referencing Grafana's refusal to pay and Instructure's euphemistic 'agreement' with attackers, and criticizes the softening of language around criminal extortion.

<img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2026/05/Splash-Template-2.jpg" alt="Weekly Update 504"><p>It&apos;s a hot topic, the old &quot;pay or don&apos;t pay&quot; for hackers not to leak your data. Since recording this a few days ago, <a href="https://x.com/grafana/status/2055827123236171827?ref=troyhunt.com" rel="noreferrer">we&apos;ve had Grafana go with the &quot;no pay&quot; approach</a>, and I&apos;ve seen a raft of commentary around other companies reaching &quot;agreements&quot;, which is a much politer way of saying &quot;we paid extortionists a ransom&quot;. I&apos;m concerned about the normalisation of ransom payments, and using language that deflects from the criminal nature of it is a big part of that. Instructure&apos;s exact words were that they &quot;reached an agreement with the unauthorised actor involved&quot;, which <em>really</em> waters down the severity of the whole thing. It looks like, for the time being, &quot;pay or leak&quot; is the new norm... along with nonsensical statements like &quot;the data was returned to us&quot; &#x1F937;&#x200D;&#x2642;&#xFE0F;</p> <!--kg-card-begin: html--> <div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 504"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 504"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 504"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 504"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/yobCTvKCLoE" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy" spellcheck="false"></iframe></div> <!--kg-card-end: html-->
Original Article
View Cached Full Text

Cached at: 05/18/26, 03:33 PM

# Weekly Update 504 Source: [https://www.troyhunt.com/weekly-update-504/](https://www.troyhunt.com/weekly-update-504/) It's a hot topic, the old "pay or don't pay" for hackers not to leak your data\. Since recording this a few days ago,[we've had Grafana go with the "no pay" approach](https://x.com/grafana/status/2055827123236171827?ref=troyhunt.com), and I've seen a raft of commentary around other companies reaching "agreements", which is a much politer way of saying "we paid extortionists a ransom"\. I'm concerned about the normalisation of ransom payments, and using language that deflects from the criminal nature of it is a big part of that\. Instructure's exact words were that they "reached an agreement with the unauthorised actor involved", which*really*waters down the severity of the whole thing\. It looks like, for the time being, "pay or leak" is the new norm\.\.\. along with nonsensical statements like "the data was returned to us" 🤷‍♂️ [![Listen on Apple Podcasts](https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/05/Listen-on-Apple-Podcasts.svg)](https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt) [![Watch and Listen on YouTube](https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2024/09/Watch-and-Listen-on-YouTube.svg)](https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&ref=troyhunt.com) [![](https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2019/10/spotify.svg)](https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt) [![Download via RSS](https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/07/Download-via-RSS.svg)](https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt) [Weekly update](https://www.troyhunt.com/tag/weekly-update/)

Similar Articles

Weekly Update 505

Troy Hunt

Troy Hunt's weekly update reports that the ShinyHunters hacking group has resurfaced with new claims against DentaQuest and Charter Communications after a brief silence following the Instructure ransom payment.

Weekly Update 503

Troy Hunt

Troy Hunt's weekly update covers Instructure's 'pay or leak' deadline from ShinyHunters, with the company remaining silent and lawsuits being prepared.

Weekly Update 494

Troy Hunt

Troy Hunt's weekly update covers a flurry of five data breaches loaded into Have I Been Pwned in just two days, including details on the Odido, KomikoAI, Quitbro, Lovora, and Provecho breaches.

Weekly Update 502

Troy Hunt

Troy Hunt's weekly update discusses how ShinyHunters uses social engineering and vishing to breach major brands, with insights from Mandiant.

Weekly Update 506

Troy Hunt

Troy Hunt discusses the ongoing ShinyHunters data breaches and dumps, noting the criminality, organizational responses, and the seemingly endless cycle of new victims appearing, such as DentaQuest and BCD Travel.