Some schools reach out to Canvas hackers as breach hits US classrooms, source says

WASHINGTON – Some schools and universities whose students’ data was stolen by a cybercriminal hacking group as part of an April breach of the educational tool Canvas individually sought to deal directly with the hackers to prevent data release, a source familiar with the matter told Reuters on May 8.

ShinyHunters, a hacking group with a string of data theft and extortion campaigns targeting major global companies, said in a May 3 post on its website that it had stolen roughly 6.65 terabytes of Canvas data related to nearly 9,000 schools worldwide that included student names, e-mail addresses and private messages between students, teachers, and other staff.

Student newspapers across the country reported this week that the hack was causing widespread disruption as students prepare for end-of-year tasks and assignments. The software is used by schools to facilitate class assignments and information sharing, as well as messages between students and school faculty.

On May 5, the group posted a message saying that Canvas’ parent company, Instructure, had “not even bothered speaking to us” to prevent a data leak, and that their demand “was not even as high as you might think it is”.

The message included a list of roughly 1,400 individual schools and districts, and invited the schools to contact them to negotiate and prevent data from being posted.

Instructure announced in a May 1 post on its support website that it was investigating a cybersecurity incident.

A post the next day, signed by chief information security officer Steve Proud, said the “information involved” included Canvas user names, e-mail addresses, student ID numbers and messages among users.

In a May 6 update, the company said the situation was resolved and that Canvas was fully operational.

On May 7, students at multiple schools reported finding a note from ShinyHunters with a link to the list of affected schools after attempting to log into Canvas.

Instructure pulled Canvas, Canvas Beta and Canvas Test offline a short time later, but restored access to Canvas four hours later.

An Instructure spokesperson said in an e-mail on May 8 that the hackers “made changes to pages that appeared when some students and teachers were logged in”.

The hackers exploited an issue related to the company’s Free-for-Teacher service, the spokesperson said, which allows non-Canvas users to try certain parts of the platform.

The company has temporarily shut down the Free-for-Teacher service, which “gives us confidence to restore access to Canvas, which is now fully back online and available for use”, the spokesperson said.

Canvas Beta and Canvas Test remain in “maintenance mode”, according to Instructure’s support site.

ShinyHunters had pulled both messages off its website as at May 7, replacing them with a message saying they were “not commenting and have no further comment to make regarding this global incident”.

A group representative declined to answer questions from Reuters sent via online chat.

Extortion and ransomware groups pull claims about victims off their websites for any number of reasons, including sometimes that a target has paid or is in negotiations.

A note sent to parents from the South Orange-Maplewood School District on Friday said the security breach occurred on April 25 and that Instructure detected unauthorised activity on April 29.

Montgomery County Public Schools in Maryland told students, staff and families in an e-mail on May 8 that Canvas was returning to service, but that the district was continuing to restrict access out of an abundance of caution “until all services have been reviewed and confirmed safe for use”.

Canvas has 30 million active users between kindergarten and college age, according to Instructure’s website. REUTERS

Christeen Pingree
Read More

Latest

Adebayo raises the alarm over police siege at SDP headquarters

Tension engulfed the national secretariat of the Social Democratic Party (SDP) on Thursday after security operatives stormed the party headquarters shortly after the screening exercise of the party’s former presidential candidate, Prince Adewole Adebayo. Adebayo alleged that the action was part of a coordinated attempt to disrupt the SDP’s presidential...

Leviste faces raps for solar business violations

Energy Secretary Sharon Garin has elevated to the Department of Justice  a complaint against Batangas Rep. Leandro Leviste over alleged violations tied to his solar company, which was granted a legislative franchise in 2019...

Mecalac to Move North American Headquarters to Fayat Group Campus in S.C.

The move to South Carolina will boost parts support, training and growth under Fayat Group, the company says...

How to reset NVRAM, PRAM, and SMC on a Mac: Intel and Apple silicon explained

Macworld When your Mac starts acting up, you’ll probably run through some common troubleshooting procedures, such as restarting it, running Disk Utility, and perhaps performing a Safe Boot. Your repair repertoire should also include a couple of additional procedures that can occasionally eliminate otherwise inscrutable problems: zapping the NVRAM and resetting the SMC...

Newsletter

Don't miss

Adebayo raises the alarm over police siege at SDP headquarters

Tension engulfed the national secretariat of the Social Democratic Party (SDP) on Thursday after security operatives stormed the party headquarters shortly after the screening exercise of the party’s former presidential candidate, Prince Adewole Adebayo. Adebayo alleged that the action was part of a coordinated attempt to disrupt the SDP’s presidential...

Leviste faces raps for solar business violations

Energy Secretary Sharon Garin has elevated to the Department of Justice  a complaint against Batangas Rep. Leandro Leviste over alleged violations tied to his solar company, which was granted a legislative franchise in 2019...

Mecalac to Move North American Headquarters to Fayat Group Campus in S.C.

The move to South Carolina will boost parts support, training and growth under Fayat Group, the company says...

How to reset NVRAM, PRAM, and SMC on a Mac: Intel and Apple silicon explained

Macworld When your Mac starts acting up, you’ll probably run through some common troubleshooting procedures, such as restarting it, running Disk Utility, and perhaps performing a Safe Boot. Your repair repertoire should also include a couple of additional procedures that can occasionally eliminate otherwise inscrutable problems: zapping the NVRAM and resetting the SMC...

EXCLUSIVE — ATF Director Robert Cekada: Hunter, AR-15 Owner, and Fan of an Armed Citizenry

Breitbart News was at the Bureau of Alcohol, Tobacco, Firearms, and Explosives (ATF) when Robert Cekada was sworn in Monday, and he sat down with us afterward to talk about growing up hunting with his dad, owning numerous AR-15s, and valuing the importance of an armed citizenry...

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID

Business groups are fighting Labor’s CGT changes. Here is where SMEs stand

Labor’s most contested tax reform in a generation cleared its first formal hurdle on Thursday and immediately ran into organised resistance. Treasurer Jim Chalmers introduced the government’s tax reform legislation to the House of Representatives on 28 May, bundling together four budget measures: the capital gains tax overhaul, new limits on negative gearing, a $250

Meet the most influential business owners from Southwest Nigeria

This article spotlights the most influential business owners from Southwest Nigeria, adjudged by their dominance in their respective sectors of the economy where they operate. The post Meet the most influential business owners from Southwest Nigeria appeared first on Nairametrics...