A significant cybersecurity incident involving Canvas, an online learning management system used by numerous schools worldwide, including in Canada, has impacted thousands of educational institutions. Among the affected users are post-secondary schools like the University of Toronto, University of British Columbia, the University of Alberta, and Western University’s Ivey Business School. Here is an overview of the breach.
What type of information was compromised?
Canvas is utilized by educators at universities, colleges, and K-12 schools to distribute various materials such as course content, assignments, media, and assessments, as well as for communication and grading purposes. The data potentially exposed includes full names, email addresses, student IDs, and personal messages, according to Instructure, the company behind Canvas.
On April 29, Instructure detected unauthorized activity through a specific teacher account. Although access was revoked, the platform was temporarily taken offline for further investigation when additional suspicious activity was identified.
Instructure reassured users that passwords, financial data, and government-issued IDs were not compromised in the breach.
How could the stolen data be exploited?
The breach raises significant concerns, according to Luke Connolly, a threat intelligence analyst at Emsisoft in Ottawa, as the leaked information could be utilized for various malicious purposes. Schools are particularly vulnerable targets since students often lack significant financial obligations, making them attractive to hackers seeking to create false identities for fraudulent activities.
Robert Falzon, the head of engineering for Canada at Check Point Software, highlighted the potential for combining data from this breach with information from other breaches to facilitate identity theft, financial fraud, and other criminal activities.
Who is behind the cyberattack?
A hacker group known as ShinyHunters has claimed responsibility for the breach, alleging that personal details of 275 million individuals, including students, teachers, and school staff, were compromised. The group, previously associated with breaches at Ticketmaster and Google’s Salesforce database, has threatened to release the stolen data unless a ransom is paid.
Reactions from students and institutions
Students across various schools, including those in the U.S. and Canada, expressed concern and confusion following the breach. Some institutions have temporarily suspended or advised against using Canvas, while others have resumed using the platform after security measures were reinforced. Schools have cautioned their communities to remain vigilant against phishing attempts and to report any suspicious activities.
Enhancing cybersecurity measures
Cybersecurity experts emphasize the shared responsibility of schools, third-party vendors, and individuals in safeguarding sensitive data. They recommend implementing robust security protocols, conducting regular security audits, and fostering awareness among users to mitigate risks of future breaches.
Protecting personal information
While students and staff may have limited control over the technology vendors chosen by their institutions, they can take proactive steps to enhance their personal cybersecurity. Suggestions include regularly updating passwords, enabling multi-factor authentication, monitoring financial accounts for unusual activities, and being cautious about sharing personal information on social media platforms.
