The University of British Columbia (UBC) and Simon Fraser University (SFU) are part of numerous educational institutions worldwide reporting a potential exposure of students’ personal data due to a cyber intrusion into the Canvas learning platform.
As per a UBC network status update, students currently logged into the software are advised to log out until receiving confirmation that it is safe to access the system again. The university became aware of a cyber incident involving Instructure, the U.S.-based parent company of Canvas, on Tuesday afternoon.
An SFU representative mentioned that approximately 9,000 educational institutions globally have been impacted by this breach. Potentially compromised information includes names, email addresses, student ID numbers, and messages exchanged among Canvas users.
Other affected institutions include the University of Toronto, Ontario College of Art and Design University, and the University of Alberta.
In response to the incident, UBC recommends that students who accessed Canvas on Thursday afternoon change their passwords immediately. Vigilance against phishing attempts and the use of strong passwords, as well as enabling multi-factor authentication, are advised to protect accounts and data.
Instructure confirmed that Canvas was temporarily taken offline upon discovering unauthorized alterations made by an external party to pages visible to logged-in students and educators. The company attributed the issue to its Free-For-Teacher accounts and has since restored full access to Canvas.
Robert Xiao, an associate professor of computer science at UBC, expressed concerns about the potential compromise of instructors’ teaching materials, emphasizing the importance of caution in the face of possible phishing attempts leveraging leaked information.
UBC and SFU, the two largest universities in British Columbia in terms of student enrollment, are closely monitoring the situation.
