Canvas Restored After Hack; Breach Linked to 'Free-For-Teacher' Accounts
Instructure has restored access to its Canvas learning management system following a widespread outage caused by a cyberattack from the ShinyHunters gang. The breach was traced to vulnerabilities in the platform's 'Free-For-Teacher' accounts, which hackers exploited to infiltrate the system and post extortion notes. While Instructure confirmed that no user data was stolen during the recent intrusion, significant data—including names, email addresses, student IDs, and private messages—was looted during an earlier breach on April 29. To secure the platform, Instructure has temporarily suspended the Free-For-Teacher service. The incident has disrupted academic activities, forcing some universities to delay final exams, and raised concerns about the privacy of underage students in K-12 districts. Although ShinyHunters threatened to leak the stolen data, reports suggest they may have removed it from their site, potentially indicating a ransom payment. Instructure asserts that external forensic partners found no evidence of current unauthorized access, but the reputational damage and potential legal repercussions remain significant concerns for the company and affected educational institutions.
Wire timeline
Canvas Restored After Hack; Breach Linked to 'Free-For-Teacher' Accounts
Instructure has restored access to its Canvas learning management system following a widespread outage caused by a cyberattack from the ShinyHunters gang. The breach was traced to vulnerabilities in the platform's 'Free-For-Teacher' accounts, which hackers exploited to infiltrate the system and post extortion notes. While Instructure confirmed that no user data was stolen during the recent intrusion, significant data—including names, email addresses, student IDs, and private messages—was looted during an earlier breach on April 29. To secure the platform, Instructure has temporarily suspended the Free-For-Teacher service. The incident has disrupted academic activities, forcing some universities to delay final exams, and raised concerns about the privacy of underage students in K-12 districts. Although ShinyHunters threatened to leak the stolen data, reports suggest they may have removed it from their site, potentially indicating a ransom payment. Instructure asserts that external forensic partners found no evidence of current unauthorized access, but the reputational damage and potential legal repercussions remain significant concerns for the company and affected educational institutions.
PCMag.com - Technology Product Reviews, News, Prices & Tips