The Canvas Breach: What Comes Next

Instructor(s)
Bryan Vorndran
, Deputy CISO, Microsoft; former head, FBI Cyber Division
Miriam Wugmeister, Partner, Morrison & Foerster; Privacy & Cybersecurity Practice Leader 

Transcript

This transcript was based on a conversation held between Bryan Vorndran, Deputy CISO, Microsoft, former head, FBI Cyber Division; and Miriam Wugmeister, Partner and Privacy & Cybersecurity Practice Leader, Morrison & Foerster. In this conversation, they discuss the cybercriminal group Shiny Hunters May 7th breach of  Instructure’s Canvas learning management system. 

Wayne Stacy  00:23

So welcome everyone to the Berkeley Center for Law and Technology’s expert series webcast. Today we have a very special program, kind of outside of our normal continuing legal education type program, really in the vein of a public service announcement. With us today, we have Miriam Wugmeister from Morrison & Foerster. You’ve seen other programs with us. If you don’t know Miriam, you should. She’s one of the nation’s leading privacy and cybersecurity lawyers, leads an enormous group at Morrison & Foerster. The way I always think about Miriam is when she talks about privacy issues, those cybersecurity issues, people listen because they know they need to understand what she knows. And today we’re lucky that she helped craft a program, brought this to our attention. So, Miriam, I want to get out of your way, and let you introduce your guests, and introduce this program.

 

Miriam Wugmeister  01:29

Thank you so much, Wayne. So, if you think you should listen to what I have to say, you really, really should listen to what Bryan Vorndran has to say. Bryan was the former head of the Cyber Division for the FBI. He saw everything relating to cyber and data security that the FBI had access to. He is now the Deputy CISO [Chief Information Security Officer] at Microsoft, and so he has this fantastic wealth of knowledge both on the private sector and the public sector. The comments that Bryan will make today, and that I will make today, are our own personal comments, and should not be attributed to either the FBI or Microsoft. What we want to talk about today is really the implications of the Canvas breach that affected so many schools. As you probably know, 40% of the schools, or something like that, in the US use Canvas, but lots of schools internationally also use Canvas. It’s a program that allows faculty and students and teachers and administrators to communicate with each other about all kinds of things relating to schools, and they had a compromise back in May, and we want to talk about that, and what the implications are for you as faculty members, as teachers, as students with respect to this incident. So, with that, Bryan, tell us what happened — tell us a little bit to set the stage.

 

Bryan Vorndran  03:03

Yeah, thanks, Miriam. Good to see you and join you here. And thanks for sharing the caveat at the top that these are my views. So I think it’s important to start with just some definitions, right? The name of the company in play here is a company named Instructure, that’s an educational technology company, and they publish what’s called the Canvas learning management system. So, as I go through this, Canvas is the tool or the product that suffered, but the company that’s in place is named Instructur, just to orient the audience to that up front. So Shiny Hunters is a cyber criminal group, they’ve been around since about 2019 and they first gained access to Instructure systems, or their infrastructure, on about April 25, 2026. They did that by exploiting a vulnerability that’s called the free for teacher account program, and it’s a feature that essentially allows educators to create Canvas accounts without institutional verification, and I also have taught over the past couple years at Johns Hopkins, and Johns Hopkins uses the Canvas product as well, and it’s essentially an interface for students and faculty — students and students posting assignments, posting syllabus, these types of things, as well as direct messages, and we’ll talk about the impact of all that as we get into this today. The compromise or the exposure window of that free for teacher program essentially ran from April 30, 2026 through May 7; that’s important because it notes the window that data could have been exfiltrated from the environment. On about May 7, Instructure did rotate privilege credentials, which essentially should have been a deterrent to keep the actors out. I use the word “should” because I’ll share here in just a minute that the actors did overcome that. So on May 3, the threat intelligence tracking platform that we know as Ransomware.live posted a copy of a ransom letter from Shiny Hunters, in which the group claimed to have data from about 275 million individuals across close to 9,000 schools. I think the total school count is around 8,800. Then on May 7, Canvas login pages at many of these institutions displayed a message from Shiny Hunters reading “Shiny Hunters has breached Instructure (again).” There’s more context here — Shiny Hunters went on to say that instead of Instructure contacting them to resolve the issue, Instructure essentially just provided some basic security patches. The validity of that, I don’t know how true that is or is not. The key takeaway here, though, is that Shiny Hunters again compromised Instructure. So, about one day after that, it appears that Instructure did pay the ransom. Under the agreement, the hackers reportedly returned all the stolen data, the compromised data, and they returned what they call shred logs, which is essentially digital forensics showing that the data copy that Shiny Hunters had was also destroyed. We will get into this — is it actually viable to believe that Shiny Hunters only had one copy of the data? Spoiler: no, we have no confidence in that. But nonetheless they did provide shred logs. I think one important note is that Instructure published some information that they said the agreement that they came to with Shiny Hunters covered all impacted customers, so it’s not just an agreement between Instructure and Shiny Hunters, but rather was an agreement between Instructure and Shiny Hunters and Instructure’s 8,800 school customers, and then obviously all the users of the platform.

 

Miriam Wugmeister  07:02

But can I just challenge you on that? Let’s just start there. I don’t think they said that it covered the users. The language was very, very specific. It said “you and your customers” — the customers are the schools. It does not say anything about the individual students or teachers.

 

Bryan Vorndran  07:20

Okay. Well, so we were going to talk about that.

 

Miriam Wugmeister  07:23

Really, really important point, right? As we get into it — what are the implications? Because I don’t think Shiny Hunters has promised anything with respect to the users.

 

Bryan Vorndran  07:33

Okay, and that’s a great setup for what we’re going to talk about here in just a few minutes. Let me just close this section, Miriam, with a comment on capability. For people listening to this who are new to the environment, or perhaps don’t have many years of experience in this environment with cyber criminal actors, or just cyber threat actors in general, these individuals are extremely capable. This is their full-time job. It is not a hobby, it is not something they do in the evening hours. This is their job, and they’ve been highly, highly profitable. I think one key takeaway for the audience is when you’re dealing with folks like Shiny Hunters, they are extremely capable, they know their line of work, and you should be respectful of that.

 

Miriam Wugmeister  08:16

Yeah, I mean, I totally agree with you, and obviously let’s just talk about Shiny Hunters, because I think that’s a good lead right there — like, who they are. Normally when we talk about different threat actor groups, we talk about nation-state actors, we talk about criminal groups that are financially motivated, but Shiny Hunters doesn’t fit into either of those buckets, right? Shiny Hunters isn’t a nation-state, and they’re not particularly financially motivated, so can you talk a little bit about who they are and what motivates them?

 

Bryan Vorndran  08:48

Sure, so to the best of my knowledge, Shiny Hunters has been around since about 2019. They have some traditional overlap with Breach Forums, which is a very well-known ecosystem for cyber criminals in the cyberspace for many years, and they are probably what I would call a parallel set of threat actors to Scattered Spider, which is a very, very well-known actor set that we’re all very familiar with. So, when you go back several years, when you look at ransomware events or data encryption events, they started as single-lever extortions, right? So actors would get into an environment, they would encrypt the environment, and then they would extort the victim — in this case, Instructure — for payment to decrypt the environment. That then moved to essentially a double-extortion environment, where actors would first get in, they would exfiltrate data, and have that data in their coffers, and then they would encrypt, so now they had two extortion levers. That’s continued to evolve, and what these threat actors have recognized is that the value here is the data, right? Companies and organizations have become better at overcoming encryption events, so the extortion lever is really, really the data. So, in this case, it’s called a pay-or-leak model — Instructure is put in a position that if they don’t pay, all of this data will be leaked, and why that’s more successful is it doesn’t require the extra level of effort of the encryption event, but also it doesn’t trigger the kind of operational disruption that draws law enforcement action immediately, such as a ransomware event. I do think the timing was deliberate and calculated. We’ve seen this — and we’ll talk about PowerSchool in the LA school district here today as well — but the timing was deliberate: it was during final exam week, a window when institutions are really, really dependent on the platform, and that puts maximum pressure on Instructure to pay. Their communications from Shiny Hunters were designed to maximize institutional leverage, right? They list organizations like Harvard and Stanford and Columbia and other elite institutions to show maximal reputational pressure. Just taking another step back on Shiny Hunters: this is not their only line of work. They are actively selling stolen data sets to other ransomware affiliates, exceeding $1 million per company. We’ll get into this more here in just a second, but the scope of the Canvas data — with this combination of student PII [personally identifiable information], private messages, institutional email addresses — is just a treasure trove for cyber criminals. So that’s who Shiny Hunters is.

 

Miriam Wugmeister  11:56

Well, just adding a little bit — when I’m saying that they’re not financially motivated, their goal, just like Scattered Spider, is to get as much attention and to cause as much disruption. This was calculated to be finals week because it wasn’t just about getting paid. Yes, they want to “leak or pay,” but what they wanted to do was just make a mess, and by doing this in the middle of finals week, everybody — schools had to move exams, schools had to figure out other ways for students to be able to turn in their papers, because all that stuff happens now through Canvas. So the big part of their goal is to be disruptive, not just to get money. I think we think, I mean, as best we know, these are young folks, right? Scattered Spider are not as sophisticated — I mean, they are sophisticated, but they’re not, like, professional. These tend to be young people who get a kick out of making trouble, right?

 

Bryan Vorndran  13:00

They do. The only thing I would nudge back on is they’re obviously very interested in making money as well, right? And they have been very successful. But yeah, I agree with you, it’s all about maximum impact — reputational damage, or in their case, reputational elevation — and then making money.

 

Miriam Wugmeister  13:19

Yeah. Okay, so talk a little bit about what was stolen here — maybe dive into that a little bit more.

 

Bryan Vorndran  13:29

Yeah, I’m happy to, and I think this is really important because it sets up the conversation about what can be done with it, right, and what individuals should do to protect themselves. Just general numbers: the attackers stole about 275 million records, about three and a half terabytes of data. That’s a lot of data — that is not an insignificant amount of data. It contains user names, email addresses, course names, enrollment information, and messages. I think most concerning, though.

 

Miriam Wugmeister  14:01

Can I add what else it includes? Schools use Canvas for accommodation issues, so if you need more time or you need some other kind of accommodation because you have a learning issue, Canvas is used for that. Some schools use it for disciplinary issues. And then there’s the direct messaging — messages between students and students, and between students and teachers — so there’s actually a lot of more private data in there. It’s not just your name and your course and that you got a B, It’s got a lot of other data in there that is definitely private.

 

Bryan Vorndran  14:40

Yeah, and I appreciate that, Miriam. And the point — let me draw out one point a little bit further in terms of these direct messages, right? As Miriam just mentioned, they’re student-to-student DMs, they’re student-to-faculty DMs, measured in several billion records in terms of the messages that were intercepted. And to Miriam’s point about the data — we’ll talk about this — names, institutional email addresses, student ID numbers — you combine that with accommodations, interests, you combine that with direct messages, it allows for great context for threat actors to do highly targeted spear phishing, right, and so that is a significant risk to the individuals who had data stolen from their accounts. The actors can use that for account takeover attempts and then downstream identity fraud, but the context that Miriam is talking about here is extremely, extremely important to the threat actors, because whether they use the data or they sell the data for use, it allows highly targeted operations against individuals — meaning against me or Miriam. One other note here: there’s a new law that came into effect in late April 2026, so it’s only about 40 days old. It’s called the Children’s Online Privacy Protection Act, and it’s a federal law essentially designed to give parents control over the personal information that websites, apps, and online services collect from children under 13 years of age. So, Canvas and Instructure serve many elementary schools and high schools — they obviously serve colleges as well — meaning that a lot of the affected individuals may be minors, right, and this leads to significant exposure under that new law. For anybody not familiar with that, it’s referred to in short as COPPA — C-O-P-P-A — but it stands for Children’s Online Privacy Protection Act. It’s worth reading about as parents to understand what the federal law says. And then, Miriam, I’m just going to close this portion with scope: we talked about this three-and-a-half-plus terabytes of data, everything from personally identifiable information to direct messages to context on course content, and the scope is not only voluminous but broad enough to enable a lot of onward activity by cyber criminals. I know we’ll talk about that here in just a second.

 

Miriam Wugmeister  17:20

I totally agree with you, and I would say it a different way: there are 275 million potential victims, right? Because every single person whose data was in there, whether it’s trivial or more private, is a potential victim, and we know that one of the things that Shiny Hunters is really good at is figuring out how to find new victims based on the data that they’ve stolen. We’ve seen Shiny Hunters do that in prior cases. We’ve seen them steal the data, get paid, promise to delete the data hahaha, and then go and extort individuals. So maybe, Bryan, talk a little bit about that — what do you think Shiny Hunters is going to do with the data?

 

Bryan Vorndran  18:07

Okay, so let me go out of order from my prep, because you just hit a point that plays very well. Number one is individual extortion, right? Shiny Hunters has already begun directly pressuring some of the approximately 8,800 Instructure customers that fell victim. They’re seeking individual payoffs for a promise not to release stolen names, email addresses, etc. And to Miriam’s point, this is 100% consistent with what Shiny Hunters did with the PowerSchool compromise in 2024, right — where victims received extortion demands even after PowerSchool had paid a ransom. So, to Miriam’s point, the guarantee that the data is not available elsewhere and is not going to be used is just nothing that someone should pay attention to. You should assume that if you are in this data set, you’re going to be targeted by Shiny Hunters, whether that’s through spear phishing or other extortion attempts. The second…

 

Miriam Wugmeister  19:09

Can I just pause right there? So there are probably two ways we know that to be true, Bryan. One is because we’ve seen it where we’ve seen victims. But also, hasn’t the FBI, when they’ve gone and actually captured infrastructure of people who claimed to have deleted the data — the FBI found that the data was actually still there? So, maybe just talk about that a little bit — we know that it’s false, right?

 

Bryan Vorndran  19:42

Yeah, it is well known in law enforcement, it is well known in the cyber incident response space, and it is well known in the cyber forensics space that these “guarantees” that the data has been deleted are simply false, right. And we can prove that over and over through many different experts in the field. So yeah, Miriam, I agree with that 100%. So, the next thing I think we want to talk about is just targeted spear phishing at scale. We’ve talked about this thematically already, but when actors have this type of exposed data — names, context about the person, student ID numbers, direct messages, courses, accommodations — that is really, really, really powerful to cyber threat actors to enable highly targeted spear phishing and account takeover attempts. So anyone listening to this should be very, very aware that they could get emails, they could get account reset requests, and those likely need to be paid very, very close attention. We’ll talk about exactly what to do about that in the last portion of our conversation, but the awareness piece for targeted spear phishing is a really, really important takeaway.

 

Miriam Wugmeister  21:04

So let’s just talk about what that might look like, Bryan. What I have seen are the types of messages that Shiny Hunters sends to individuals, and they’re really, really convincing. Can you maybe just talk a little bit about what the note — whether it’s an email or a text — what does it look like, and how they do it?

 

Bryan Vorndran  21:27

Yeah, so I think one quick note here — and Miriam and I know this — the evolution of spear phishing has increased in velocity because of AI, right. Gone are the days where people who did not have proficiency in the English language were writing broken English emails to people here in the United States, or elsewhere. Now, that is all machine-generated, and so those targeted spear phishing emails can come from the school that you are currently enrolled in, and they would say things like, “Hey, based on X, Y, and Z, we need you to take this action — please click on this link to fill out this new form for the next school year.” That’s just a very basic example, but it would look and feel identical to other messages you have received from the school. You should really look at the email headers on those messages: who did they come from? Can you guarantee that those email addresses are 100% affiliated with the academic institution you’re attending? Just a really good practice is: don’t click on a URL in an email, don’t click on an attachment in an email. You can always email your administrator, your school, and ask, “Hey, is this legitimate?” But it would look and feel like any other messages you’ve already received from the school, because the actors have access to what those emails look like, and they can tailor the emails directly to you based on what they know about you.

 

Miriam Wugmeister  23:02

Okay, now talk about what an extortion message from Shiny Hunters is going to look like.

 

Bryan Vorndran  23:11

Yeah, it could be anything from harassment to escalation. They could say hey–I’ll give you the worst-case scenario: “we have compromising videos or compromising photographs of you” — what we refer to in the industry as light “sextortion,” right, where there’s no guarantee that the actors actually have those images or those videos, but that would be the extreme case of what the actors would claim to have, and that you should pay them to prevent the release of those images or those videos.

 

Miriam Wugmeister  23:44

Can I just add to that one? So what those messages are going to say — and this is going to be to a kid — it’s going to say, “Hey, you go to Middlesex High School, and you have Mr. Smith as your homeroom teacher, and we stole your data, but not only did we get the data from your school, but we got into your phone and your personal computer, and if you don’t give us $1,000 we’re going to tell your parents and put on the internet that you’ve been watching porn.” The part is they’re going to use the information that they stole from Canvas and then make up something — the sextortion part — to try and coerce people into paying them money. It’s unbelievably effective and super scary when you get one of those messages. Right, Bryan?

 

Bryan Vorndran  24:32

Yep, absolutely. That’s a really good practical description of what it would look and feel like, Miriam, I appreciate you weighing in on that. Yea, I mean, I’ll just say this now, the number one thing for people to do — especially students under the age of 18 — if they receive one of these, is: do not reply, right? Just pause, take some time to think, engage your parents, even if you think there’s risk about personal reputation for yourself. Just pause, engage your parents, engage law enforcement, and do not reply. But Miriam, you did a great job explaining what it would look and feel like, using the data that they have. Certainly one could assume that there is inappropriate conversation in all of these direct messages that students or faculty may not want out in the open world from a reputational damage perspective. That’s just another spin on what Miriam described as what an extortion note would look like to gain leverage over you. But again, the key takeaway here is like pause, right, do not reply immediately, do not panic, right? Pause, engage your parents, engage law enforcement, and let’s walk through this together.

 

Miriam Wugmeister  25:48

Yeah, and I think that’s exactly right. But the other thing is, you know, they promised to have deleted it — they, in theory, sent proof that they deleted it — and yet they’re using that information to extort you, which means even if you were to pay them, it will mean nothing. They are not going to delete the data; they’re going to do whatever they’re going to do to keep getting leverage. And if you are one of the people who replies to them, and this goes to your point about using AI — you have 275 million potential victims, so they’re going to use AI to do auto-generated extortion notes. I would use a bot to do that — that’s what I would do if I were them. And whoever replies is going to be the one that moves to the top of the pack, and the one that they’re then going to be more serious about trying to extort. Brian, isn’t that what you think is going to happen?

 

Bryan Vorndran  26:42

Absolutely. Yes, they are not to be trusted. So even if they tell you that you pay and this all goes away, it’s not true. Just deal with the reality of the situation that they have, in the short and long term, your data or your direct messages, and pause — get some help.

 

Miriam Wugmeister  27:03

Right. And this isn’t just Miriam and Bryan giving this advice. The FBI has actually put out a public service announcement on exactly this topic, and we’ll include a link to that at the end of this session, but that is exactly the advice from the FBI — saying exactly what we’re saying, which is: don’t engage, don’t pay, call law enforcement, call somebody you trust. Engaging and paying are not going to lead to the conclusion that you want, because the other thing to know is they didn’t get into your personal computer, they didn’t get into your phone. So the allegations about the sextortion — particularly, or any other private information that wasn’t in Canvas is just a lie.

 

Bryan Vorndran  27:51

Yep. And Miriam, let me double down — I think that is a really important message for the audience. What we know today is that what was compromised was in Canvas only. It did not have downstream impact to personal email addresses, to personal computers, to phones. Now, with that said, one of the most important things you can do right now, if you’re in the audience, is to change your passwords on all your personal accounts and enable multi-factor authentication on those accounts, because it is obviously possible that the actors have access to some of your personal communication information, and you want to take the right steps to protect that. And Miriam, before I forget, I do want to talk about online identity fraud against minors before we move on. So we talked about extortion — everything from content in direct messages or making claims that there’s compromising pictures or videos — and that is here and now, very, very relevant for anyone who has had data stolen. As we look forward, just say six months, 12 months: another massive risk is identity fraud, right? Because there is enough information about each of the students in the data that was stolen that it’s very, very easy for these actors to open up fraudulent credit cards or fraudulent bank accounts. So it is very important that the audience also pays attention to credit monitoring services and things of that sort, because this is how the data gets used to further illicit schemes, not only for Shiny Hunters, but for other affiliates that Shiny Hunters sells the data to. Miriam, I just wanted to hit that point.

 

Miriam Wugmeister  29:43

No, and particularly for people under 18, right? You can’t get a credit report if you’re under 18 — it’s very hard to do. What we have seen happening is people’s kids turn 18, they get their first free credit report from the credit bureaus, and find that their child is half a million dollars in debt even though they’ve never done anything. So I think it’s a really, really good point that, particularly for minors, one of the ways in which the bad guys are exploiting this kind of information is by opening up various credit facilities in the name of the minors, and nobody’s checking because they can’t.

 

Bryan Vorndran  30:22

Yep.

 

Miriam Wugmeister  30:24

All right, so Bryan, what happened — what haven’t we hit?

 

Bryan Vorndran  30:28

I think we’ve hit everything.

 

Miriam Wugmeister  30:30

The only other thing just to hit is to make the point which you made, which is: despite the fact that Shiny Hunters said they wouldn’t extort the schools, we are seeing some evidence that the schools are being extorted. And so if you’re a school, there are lots and lots of resources for you within your organization — with your lawyers, talk to your general counsel, talk to law enforcement — make sure that you’re being very thoughtful, because again, paying is likely to not have the data the data is not going to be deleted. They’ve already broken their word once, they’re going to do it again. So just be very thoughtful about how you engage, whether to engage, and know that law enforcement can actually be incredibly helpful in this context.

 

Bryan Vorndran  31:23

Yeah, Miriam, if you give me an opportunity to just sum this up in three key takeaways: number one, the scope of the data is massive — in terms of traditional peronsally identiable information all the way through fantastic context for the cyber threat actor Shiny Hunters — and that enables very, very specific and capable spear phishing, extortion attempts, online identity fraud, et cetera. Number two is Shiny Hunters’ modus operandi (MO), historically and probably presently, is that they will keep a copy of the data and they will try to extort individuals moving forward. So any trust in the fact that this is going away is misplaced trust, and vigilance is extremely important. And number three is self-awareness and vigilance for the individual — the individual student, the individual faculty member — to pay attention to emails and text messages they’re getting. As Miriam raised the concern about not getting credit reports under the age of 18, which is very true, for those of us over the age of 18 by a lot like myself, we should be monitoring those things very, very rigorously. So that’s how I would break down the three key takeaways: the scope of what was stolen and what it enables; Shiny Hunters’ historic and present MO; and then vigilance moving forward.

 

Miriam Wugmeister  32:54

Fantastic, thanks so much, Bryan.

 

Bryan Vorndran  32:56

Thanks, Miriam.

 

Wayne Stacy  32:57

Before you leave, I’d love to ask one question here, and that is the ability to roll up data from multiple sources. So, if I have all the Canvas data, one of my concerns would be that makes me easy to identify on TikTok, it makes me easy to identify on Instagram. So now you start rolling up more data to even make a stronger pitch: “I have these pictures from you at this party” — I can kind of connect through. Is that something that you’re seeing or something that people should be worried about that’s an even better spear phishing attack, because I know…

 

Bryan Vorndran  33:37

I can take that if you want me to. Wayne I think that the core answer to your question is yes. Let me try to put some context around that. The ability to aggregate data with machine learning and AI is obviously at scales we’ve never seen before, right. So that aggregation of data to tell a more fulsome story at an individual level is obviously very real and very present, and that’s why the answer to your question is yes. But my takeaway or my guidance to the audience would be this: this is why it’s so important to monitor all communications coming into all of your direct messages, to your email box, to your phone, right. It’s not just email or phone and if  I wasn’t clear on that that’s me, but it’s all of your communication accounts, all of your social media accounts. So, the core answer to your question is yes. I just think everybody needs to take a broader view of how to protect themselves.

 

Miriam Wugmeister  34:42

And I’ll just add — Shiny Hunters already has 270 million records already. Will they, can they aggregate it? They can also not onluy aggregate with other public stuff, but they have other companies and organizations that they’ve compromised. So there may be different methods: for students they may just use what’s in Canvas and make some stuff up, like we talked about, but for a senior faculty member at a university, for example, they could take the information from Canvas plus other information and make that a pretty scary extortion attempt. We have seen this from other Shiny Hunters compromises — cruise lines and other organizations. They’re very good at creating concern in the recipient. And that’s not just for the kids, thats for sophisticated grown-ups. But you’re absolutely right, Wayne, it’s a great point.

 

Wayne Stacy  35:55

Well, I want to thank both of you for sharing this information. Being at a university, you worry about the students and what they’re doing, and being a father of a high school kid, I worry even more there because they don’t hear this kind of information, they don’t have access to it sometimes, and sometimes the families don’t. So, what you’re doing is a great service. I really appreciate it.

 

Bryan Vorndran  36:21

Thanks, Wayne. Thanks, Miriam.

 

Miriam Wugmeister  36:23

Thank you.

This transcript was created with an automated transcription service and reviewed by a human