A major cyberattack on the Canvas platform, widely utilized in educational settings, has caused significant disruptions for schools and universities throughout the United States. The attack, attributed to the cybercriminal group ShinyHunters, involved defacing the Canvas login page with a ransom demand, claiming to possess data from 275 million students and faculty members across nearly 9,000 institutions. In response, Instructure, the parent company of Canvas, temporarily disabled the platform to mitigate the situation. Earlier this week, Instructure acknowledged a data breach and indicated that the stolen data included user names, email addresses, and student IDs, but no sensitive information like passwords or financial details was reported compromised. Despite this, the timing of the attack is particularly concerning as many institutions are currently conducting final exams. The ransom note urged affected schools to negotiate their own payments, regardless of Instructure's actions. Experts have criticized Instructure's handling of the situation, noting this is not the first breach by ShinyHunters. The outcome now hinges on how educational institutions respond to the breach and whether they will push for accountability or remain silent.
Canvas Data Breach Affects Educational Institutions Across the U.S.
A significant data breach targeting Canvas has disrupted educational activities nationwide, with a cybercrime group threatening to leak sensitive information.
