Weekly Update 504

Troy Hunt News

Summary

Troy Hunt's weekly update discusses the normalization of ransomware payments, referencing Grafana's refusal to pay and Instructure's euphemistic 'agreement' with attackers, and criticizes the softening of language around criminal extortion.

<img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2026/05/Splash-Template-2.jpg" alt="Weekly Update 504"><p>It&apos;s a hot topic, the old &quot;pay or don&apos;t pay&quot; for hackers not to leak your data. Since recording this a few days ago, <a href="https://x.com/grafana/status/2055827123236171827?ref=troyhunt.com" rel="noreferrer">we&apos;ve had Grafana go with the &quot;no pay&quot; approach</a>, and I&apos;ve seen a raft of commentary around other companies reaching &quot;agreements&quot;, which is a much politer way of saying &quot;we paid extortionists a ransom&quot;. I&apos;m concerned about the normalisation of ransom payments, and using language that deflects from the criminal nature of it is a big part of that. Instructure&apos;s exact words were that they &quot;reached an agreement with the unauthorised actor involved&quot;, which <em>really</em> waters down the severity of the whole thing. It looks like, for the time being, &quot;pay or leak&quot; is the new norm... along with nonsensical statements like &quot;the data was returned to us&quot; &#x1F937;&#x200D;&#x2642;&#xFE0F;</p> <!--kg-card-begin: html--> <div><div style="width: 170px; display: inline-block; margin-right: 3px;"><a href="https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/05/Listen-on-Apple-Podcasts.svg" alt="Weekly Update 504"></a></div><div style="width: 175px; display: inline-block; margin-right: 3px;"><a href="https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2024/09/Watch-and-Listen-on-YouTube.svg" alt="Weekly Update 504"></a></div><div style="width: 118px; display: inline-block; margin-right: 3px;"><a href="https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2019/10/spotify.svg" class="kg-image" alt="Weekly Update 504"></a></div><div style="width: 120px; display: inline-block;"><a href="https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt"><img src="https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/07/Download-via-RSS.svg" alt="Weekly Update 504"></a></div><iframe width="100%" height="480" src="https://www.youtube.com/embed/yobCTvKCLoE" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen loading="lazy" spellcheck="false"></iframe></div> <!--kg-card-end: html-->
Original Article
View Cached Full Text

Cached at: 05/18/26, 03:33 PM

# Weekly Update 504 Source: [https://www.troyhunt.com/weekly-update-504/](https://www.troyhunt.com/weekly-update-504/) It's a hot topic, the old "pay or don't pay" for hackers not to leak your data\. Since recording this a few days ago,[we've had Grafana go with the "no pay" approach](https://x.com/grafana/status/2055827123236171827?ref=troyhunt.com), and I've seen a raft of commentary around other companies reaching "agreements", which is a much politer way of saying "we paid extortionists a ransom"\. I'm concerned about the normalisation of ransom payments, and using language that deflects from the criminal nature of it is a big part of that\. Instructure's exact words were that they "reached an agreement with the unauthorised actor involved", which*really*waters down the severity of the whole thing\. It looks like, for the time being, "pay or leak" is the new norm\.\.\. along with nonsensical statements like "the data was returned to us" 🤷‍♂️ [![Listen on Apple Podcasts](https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/05/Listen-on-Apple-Podcasts.svg)](https://itunes.apple.com/au/podcast/troy-hunts-weekly-update-podcast/id1176454699?ref=troy-hunt) [![Watch and Listen on YouTube](https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2024/09/Watch-and-Listen-on-YouTube.svg)](https://www.youtube.com/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&ref=troyhunt.com) [![](https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2019/10/spotify.svg)](https://open.spotify.com/show/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt) [![Download via RSS](https://storage.ghost.io/c/fb/33/fb3391dc-723d-4e74-b95a-d641b5feb38e/content/images/2018/07/Download-via-RSS.svg)](https://omny.fm/shows/troy-hunt-weekly-update/playlists/podcast.rss?ref=troy-hunt) [Weekly update](https://www.troyhunt.com/tag/weekly-update/)

Similar Articles

Weekly Update 505

Troy Hunt

Troy Hunt's weekly update reports that the ShinyHunters hacking group has resurfaced with new claims against DentaQuest and Charter Communications after a brief silence following the Instructure ransom payment.

Weekly Update 503

Troy Hunt

Troy Hunt's weekly update covers Instructure's 'pay or leak' deadline from ShinyHunters, with the company remaining silent and lawsuits being prepared.

Weekly Update 517: Cyber Ransoms

Troy Hunt

This weekly update discusses the current state of cyber ransoms, highlighting how ransomware attacks are often conducted by inexperienced actors and the legal repercussions for breached companies.

Weekly Update 519: Breaches & Data Integrity

Troy Hunt

Troy Hunt's weekly update covers his busy week with talks on 3D printing and infosec, data breaches, and IoT projects, focusing on security and data integrity topics.

Weekly Update 494

Troy Hunt

Troy Hunt's weekly update covers a flurry of five data breaches loaded into Have I Been Pwned in just two days, including details on the Odido, KomikoAI, Quitbro, Lovora, and Provecho breaches.