crime
A hacking group that claimed responsibility for attacking Canvas’s parent company said it had accessed the data of more than 275 million people in 9,000 schools.
Harvard University is one of the schools that experienced a Canvas outage on Thursday. Sophie Park/The New York Times
Canvas, a platform used by more than 8,000 K-12 universities and schools for course sites, assignments and communications, was closed for several hours on Thursday. A hacking group claimed responsibility for a data breach that affected the company that owns the platform, putting the personal data of millions of students and teachers at risk.
Several prominent universities, including the University of Michigan and Harvard Universityalerted students on Thursday that Canvas was unavailable. Across the country, students were preparing for or already taking their final exams.
Instructure, which provides its Canvas software to about half of the colleges and universities in North America, said the software is undergoing maintenance and expects it “to be up and running soon” in an alert posted on its website Thursday evening. The company said earlier that it was investigating why the program was unavailable.
Instructure did not immediately respond to a request for comment.
ShinyHunters, the hacking group that claimed responsibility for the Instructure data breach, said it accessed data from more than 275 million people across nearly 9,000 schools, according to a ransom note shared on May 3 by Ransomware.live, which monitors ransomware groups.
An email shared with students at Barnard College in New York said the outage appeared to be “the result of a previous cyberattack on Instructure.”
Instructure revealed on May 1 that it had been involved in a “cybersecurity incident committed by a criminal threat actor.” Steve Proud, chief information security officer at Instructure, said the company has enlisted forensic experts to minimize the impact of the breach.
In an update shared the next day, Proud said the compromised information included personally identifiable information such as names, email addresses, student ID numbers and Canvas messages.
He said the company found no evidence that passwords, dates of birth, government IDs or financial information were compromised. Proud added that the breach had been “contained” as of May 2.
“Canvas is fully operational, and we do not see any ongoing unauthorized activity,” the company said on its website on Wednesday.
ShinyHunters, believed to have formed around 2020, claimed responsibility for the hack on Thursday in a message that appeared on student Canvas pages and was obtained by The New York Times.
The group said it breached Instructure “again” after the company failed to contact it to resolve its security issue. Instead, the group claimed that Instructure “ignored us and made some security patches.”
ShinyHunters said in its letter that it will leak an unspecified amount of data on May 12 if it does not hear from Instructure. In its May 3 ransom note, the group threatened to leak “several billion private messages between students and teachers.”
The group also encouraged the affected schools, including Duke University and the University of Maryland, to consult with cybersecurity and communications experts to “negotiate a settlement.”
Some students later saw the ShinyHunters message change to an alert stating that Canvas is “currently undergoing scheduled maintenance.” The outage appeared to be active as of 8 p.m
Not much is known about ShinyHunters, but their goal appears to be to obtain and sell personal records. The hacking group has previously targeted Ticketmaster, Microsoft, AT&T and dozens of other companies in the US and elsewhere.
The group has also recently targeted education companies, including Infinite Campus, an information system for K-12 students, and McGraw Hill, a prominent textbook publisher.
This article originally appeared on New York Times.
Subscribe to our newsletter today
Get everything you need to know to start your day, delivered straight to your inbox every morning.