Troy Hunt's weekly update discusses the normalization of ransomware payments, referencing Grafana's refusal to pay and Instructure's euphemistic 'agreement' with attackers, and criticizes the softening of language around criminal extortion.
<img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2026/05/Splash-Template-2.jpg" alt="Weekly Update 504"><p>It's a hot topic, the old "pay or don't pay" for hackers not to leak your data. Since recording this a few days ago, <a href="https://x.com/grafana/status/2055827123236171827?ref=troyhunt.com" rel="noreferrer">we've had Grafana go with the "no pay" approach</a>, and I've seen a raft of commentary around other companies reaching "agreements", which is a much politer way of saying "we paid extortionists a ransom". I'm concerned about the normalisation of ransom payments, and using language that deflects from the criminal nature of it is a big part of that. Instructure's exact words were that they "reached an agreement with the unauthorised actor involved", which <em>really</em> waters down the severity of the whole thing. It looks like, for the time being, "pay or leak" is the new norm... along with nonsensical statements like "the data was returned to us" 🤷‍♂️</p>
<!--kg-card-begin: html-->
<div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 504"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&ref=troyhunt.com"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 504"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 504"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 504"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/yobCTvKCLoE" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy" spellcheck="false"></iframe></div>
<!--kg-card-end: html-->
# Weekly Update 504
Source: [https://www.troyhunt.com/weekly-update-504/](https://www.troyhunt.com/weekly-update-504/)
It's a hot topic, the old "pay or don't pay" for hackers not to leak your data\. Since recording this a few days ago,[we've had Grafana go with the "no pay" approach](https://x.com/grafana/status/2055827123236171827?ref=troyhunt.com), and I've seen a raft of commentary around other companies reaching "agreements", which is a much politer way of saying "we paid extortionists a ransom"\. I'm concerned about the normalisation of ransom payments, and using language that deflects from the criminal nature of it is a big part of that\. Instructure's exact words were that they "reached an agreement with the unauthorised actor involved", which*really*waters down the severity of the whole thing\. It looks like, for the time being, "pay or leak" is the new norm\.\.\. along with nonsensical statements like "the data was returned to us" 🤷♂️
[](https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt)
[](https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&ref=troyhunt.com)
[](https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt)
[](https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt)
[Weekly update](https://www.troyhunt.com/tag/weekly-update/)
Troy Hunt's weekly update reports that the ShinyHunters hacking group has resurfaced with new claims against DentaQuest and Charter Communications after a brief silence following the Instructure ransom payment.
Troy Hunt's weekly update covers Instructure's 'pay or leak' deadline from ShinyHunters, with the company remaining silent and lawsuits being prepared.
Troy Hunt's weekly update covers a flurry of five data breaches loaded into Have I Been Pwned in just two days, including details on the Odido, KomikoAI, Quitbro, Lovora, and Provecho breaches.
Troy Hunt discusses the ongoing ShinyHunters data breaches and dumps, noting the criminality, organizational responses, and the seemingly endless cycle of new victims appearing, such as DentaQuest and BCD Travel.