Normal view

There are new articles available, click to refresh the page.
Before yesterdayCyberScoop

764 splinter group leader sentenced to 40 years in jail

9 July 2026 at 10:34

A San Antonio man who sexually exploited children while leading 8884, an offshoot of the notorious violent extremist collective 764, was sentenced to 40 years in prison in federal court Wednesday, the Justice Department said. 

Alexis Aldair Chavez began associating with 764 as a child in 2022 when a co-conspirator introduced him to 7997, one of many 764 offshoots affiliated with the Com. The sprawling nihilistic network of thousands of people, typically between 11 and 25 years old, seek to foster social unrest by destroying civilized society through the corruption and exploitation of children and other vulnerable populations.

The 19-year-old, also known as “Zack” and “Zack8884,” attempted to coerce a girl to commit suicide and blackmailed another girl into self-mutiliation, animal torture and illicit content production in late 2023, according to court records. He later worked with multiple co-conspirators and blackmailed some of his victims to coerce other girls to degrade themselves on camera and produce child sexual abuse material (CSAM).

Chavez was arrested and has been detained without bail since October 2024. He pleaded guilty to multiple crimes involving the sexual exploitation of children in December 2025 and faced up to 60 years in prison for racketeering, distribution and possession of CSAM.

“Chavez’s crimes reveal the ruthless exploitation and manipulation at the core of nihilistic violent extremist groups,” John A. Eisenberg, assistant attorney general for national security, said in a statement. 

“These organizations target children as part of their broader mission to spread terror. These groups ultimately seek nothing less than the destruction of our society,” he added. “The National Security Division will use every resource at its disposal to identify and prosecute 764-linked criminality and to protect the most innocent among us from these predators.”

The indictment filed against Chavez in the U.S. District Court for the Western District of Texas details a series of horrifying crimes he committed with co-conspirators and some of his victims. 

Prosecutors said Chavez and a co-conspirator coerced a girl to cut her tongue, and torture and kill a cat on a live video call in late 2023. He and co-conspirators also, that same month, groomed and extorted several other girls to commit self harm and degrade themselves on camera.

Allison Nixon, chief research officer at Unit 221B, told CyberScoop the sentence is appropriate even if people understandably dislike imprisoning young people. 

“In this space, a certain personality profile is highly predictive of who will risk a prison sentence like this: an obsession with maximizing harm,” she said. 

“Reoffending after release is a huge problem. All major global hacking incidents from the Com are done by serial reoffenders — all obsessed with harmfulness, some graduated from the 764 sextortion space,” Nixon added.

Too many jurisdictions are naive in how they handle cases involving members or associates of the Com, allowing these criminals to go home to parents who won’t supervise them, she said.

Officials pressed on this in their reaction to Chavez’s sentencing as well. “Parents need to know what their children are doing online and must stay engaged, ask difficult questions, and not fall into the trap of believing their child is ‘just playing games’ or ‘just talking with their friends,’” Justin R. Simmons, U.S. attorney for the Western District of Texas, said in a statement. 

“There is darkness present within many people in this world that want nothing more than to see the United States and western civilization fail. There is no limit to the actions these individuals will take to accomplish that goal, including torturing and abusing children,” Simmons added.

Chavez, who was also ordered to pay $10,000 in restitution and serve lifetime supervised release, joins other 764 members already serving long sentences for similar crimes. Bradley Chance Cadenhed, who founded 764 as a 15-year-old in 2021, was arrested later that year and sentenced to 80 years in prison in 2023. 

When the FBI executed a search warrant at Chavez’s residence in July 2024, prosecutors said he came out the backdoor and threw his phone over a neighbor’s fence in an attempt to hide evidence.

Chavez’s sentencing follows a period of heightened law enforcement activity, which has netted arrests of multiple alleged 764 leaders and members. Some of the alleged 764 members arrested since 2025  include: Leonidas Varagiannis and Prasan Nepal, Baron Cain Martin, Tony Christopher Long, Erik Lee Madison, Zachary Sweeney and Aaron Corey

“True rehabilitation is the best outcome, but no one knows how,” Nixon said. 

“The total number of offenders who fit this harm-obsessed profile is vanishingly small. Giving them maximum sentences won’t overflow jails,” she added. 

Law enforcement and judges have to be realistic about what it takes to prevent the victimization of children, and handing down lifelong or lengthy prison sentences strikes the right balance between the rights of the offender and society, Nixon said.

FBI officials and agents who track these offenders and gather evidence on their crimes draw similar conclusions. 

“Nothing is more abhorrent than those who prey on children and other vulnerable members of our society and this defendant will pay a steep price for doing just that,” Coult Markovsky, acting assistant director of the FBI’s counterterrorism division, said in a statement.

“This sentencing demonstrates the FBI’s unwavering resolve to identify, hunt down, investigate, and prosecute criminals like Chavez who prey on children through violent online networks, including 764, and orchestrate horrific, unspeakable acts of exploitation and violence,” Daniel Faith, special agent in charge of the FBI San Antonio field office, said in a statement. 

“These predators use social media, messaging apps, gaming platforms, chat rooms, and video services to groom vulnerable children,” Faith added. “Staying engaged in your child’s online life, maintaining open communication, recognizing the warning signs, and reporting suspicious online activity to law enforcement are critical to stopping these offenders.”

The post 764 splinter group leader sentenced to 40 years in jail appeared first on CyberScoop.

Instructure claims hackers returned stolen Canvas data after an extortion standoff

11 May 2026 at 19:31

Instructure, the company behind Canvas, said it reached an agreement with the cybercriminals who threatened to leak a trove of sensitive data they claim was stolen during a prolonged cyberattack on the widely used education tech platform.

Pressure was mounting on the company as widespread outages left schools, students and teachers temporarily unable to access critical data late last week when the company took Canvas offline after the attackers defaced the platform’s login page. By Friday, the company said Canvas — a central hub for K-12 and university coursework, exams, grades and communication — was back online and fully operational. 

ShinyHunters, a decentralized crew of prolific cybercriminals that researchers affiliate with The Com, claimed responsibility for the attack on its data leak site and was attempting to extort the company for an unknown ransom amount. 

Instructure didn’t outright say it paid a ransom, but insisted the agreement provided all necessary assurances. “The data was returned to us. We received digital confirmation of data destruction (shred logs),” the company said in an update Monday.

“We have been informed that no Instructure customers will be extorted as a result of this incident, publicly or otherwise,” the company added. “This agreement covers all impacted Instructure customers, and there is no need for individual customers to attempt to engage with the unauthorized actor.”

The threat group initially set a deadline of May 6 — four days after Instructure previously said the incident was contained — claiming it stole 3.65 terabytes of data spanning 275 million records across 8,809 school systems. 

When that deadline passed without payment, ShinyHunters escalated its pressure on the company by “injecting an extortion message directly into the Canvas login pages of roughly 330 institutions, and pivoted to school-by-school extortion with a current deadline of May 12,” Cynthia Kaiser, senior vice president of Halcyon’s Ransomware Research Center, told CyberScoop.

The additional public pressure prompted Infrastructure to take Canvas offline, disrupting schoolwork and access to critical systems nationwide. 

Instructure CEO Steve Daly apologized over the weekend for the company’s inconsistent communication and deficient public response to the cyberattack. 

“Over the past few days, many of you dealt with real disruption. Stress on your teams. Missed moments in the classroom. Questions you couldn’t get answered. You deserved more consistent communication from us, and we didn’t deliver it. I’m sorry for that,” he said in a statement.

Daly acknowledged that the attack, which remains under investigation aided by CrowdStrike, exposed usernames, email addresses, course names, enrollment information and messages. He insisted that course content, submissions and credentials were not compromised.

The temporary but widespread disruption has spurred broad concern across the education sector as ransomware experts and threat hunters continue to track developments. The cyberattack also caught the attention of lawmakers on Capitol Hill. 

The House Homeland Security Committee on Monday published a letter to Daly seeking a briefing with him or a senior leader at Instructure by May 21. 

“The recurrence of an intrusion within days of an initial breach disclosure, and Instructure’s apparent failure to fully remediate the underlying vulnerabilities during that window, raise serious questions about the company’s incident response capabilities and its obligations to the institutions and individuals whose data it holds,” House Homeland Security Chairman Andrew Garbarino, R-N.Y., wrote in the letter to Daly.

The committee wants to learn more about the “circumstances of both intrusions, the the nature and volume of data accessed, the steps Instructure has taken and is taking to contain the threat and notify affected institutions, and the adequacy of the company’s coordination with federal law enforcement and the Cybersecurity and Infrastructure Security Agency,” he added. 

CISA did not describe the extent of its involvement in Instructure’s response. “CISA is aware of a potential cyber incident affecting Canvas. As the nation’s cyber defense agency, we provide voluntary support and cybersecurity services to organizations in responding to and recovering from incidents,” Chris Butera, the agency’s acting executive assistant director for cybersecurity, said in a statement.

Instructure’s timeline of the attack has changed and remains incomplete. The company said it first detected unauthorized activity in Canvas on April 29 and immediately revoked the attacker’s access and initiated an incident response. Researchers not directly involved with the formal investigation said ShinyHunters gained access to Canvas at least a few days earlier.

The follow-on malicious activity on May 7 — the defacement of public login pages — was tied to the same incident, the company said. 

“We have since confirmed that the unauthorized actor carried out this activity by exploiting an issue related to our Free-For-Teacher accounts. This is the same issue that led to the unauthorized access the prior week. As a result, we have made the difficult decision to temporarily shut down Free-For-Teacher accounts,” the company said in an updated post about the incident.

Instructure did not answer questions about the vulnerability or explain how attackers intruded its systems. The company said it also revoked privileged credentials and access tokens for affected systems, rotated internal keys, restricted token creation pathways, and deployed additional security controls and monitoring.

Canvas is fully operational and safe to use, the company said, adding that CrowdStrike has reviewed known indicators of compromise and “found no evidence that the threat actor currently has access to the platform.”

Access still remains spotty and unavailable for some Canvas users as school districts restore the platform in phases after conducting their own internal checks.

Halcyon published an alert about the attack Friday, including a screenshot of the message that some school staff, guardians and students encountered before Instructure took the learning management system offline.

ShinyHunters is a notorious data theft extortion group that previously hit major cloud platforms, including Salesforce and Snowflake, via voice phishing, credential theft and supply-chain attacks. 

Education is a recurring and consistent target for cybercriminals, accounting for more than 250 ransomware attacks globally last year, according to Halcyon. 

Yet, the scope of the attack on Canvas “makes this one of the largest single education-sector exposures we’ve tracked,” Kaiser said.

“By compromising a shared platform used across thousands of schools, ShinyHunters hit the entire education sector in one move, which is the same playbook Clop ran against Oracle EBS customers last fall,” she added. “Among 2026 incidents against critical infrastructure, this is at or near the top for education-sector impact, and it highlights a trend of third-party software vendors now being part of an attack surface, and causing cascading effects across an entire sector.”

Cybersecurity professionals focused on ransomware and data theft extortion consistently encourage victims to not pay ransoms, but they also often acknowledge that companies have to make tough decisions based on their own interests and the security of their customers or users caught up in the aftermath.

Allison Nixon, chief research officer at Unit 221B, said the threat group claiming responsibility for the attack should not be trusted. 

“They are claiming they will delete the data after they are paid, and if they are not paid that they will leak the data,” she told CyberScoop. “This is in line with the past data extortion scams run by the same and related Com actors, who have made false statements to victims and to the public in the past.”

Instructure acknowledged that its agreement with the attackers isn’t ironclad. “While there is never complete certainty when dealing with cybercriminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible,” the company said.

Daly — a longtime security executive who was previously CEO at Ivanti — ended his mea culpa with a pledge to improve communications and provide a summary of a forensics report soon.

“Last week, we made a call to get the facts right before speaking publicly. That instinct isn’t wrong, but we got the balance wrong. We focused on fact-finding and went quiet when you needed consistent updates. You’ve been clear about that, and it’s fair feedback. We will change that moving forward,” he said. 

“Rebuilding trust takes time,” Daly added. “We’re going to earn it back through consistent action and honest communication.”

Update: May 12, 11:00 am: This story has been updated to reflect that Instructure announced they have reached a deal with ShinyHunters.

The post Instructure claims hackers returned stolen Canvas data after an extortion standoff appeared first on CyberScoop.

❌
❌