Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. New, from me: Canvas Breach Disrupts Schools and Colleges Nationwide

New, from me: Canvas Breach Disrupts Schools and Colleges Nationwide

Scheduled Pinned Locked Moved Uncategorized
canvasbreachshinyhuntersinstructure
9 Posts 7 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchangeB This user is from outside of this forum
    briankrebs@infosec.exchange
    wrote last edited by
    #1

    New, from me: Canvas Breach Disrupts Schools and Colleges Nationwide

    "An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions."

    "Canvas parent firm Instructure [NYSE:INST] responded to today's defacement attacks by disabling the platform, which is used by thousands of schools, universities and businesses to manage coursework and assignments, and to communicate with students."

    Lots more here:

    Link Preview Image
    Canvas Breach Disrupts Schools & Colleges Nationwide – Krebs on Security

    favicon

    (krebsonsecurity.com)

    #canvas #breach #shinyhunters #instructure

    jtk@infosec.exchangeJ zl2tod@mastodon.onlineZ beachbum@mastodon.sdf.orgB 3 Replies Last reply
    1
    0
    • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

      New, from me: Canvas Breach Disrupts Schools and Colleges Nationwide

      "An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions."

      "Canvas parent firm Instructure [NYSE:INST] responded to today's defacement attacks by disabling the platform, which is used by thousands of schools, universities and businesses to manage coursework and assignments, and to communicate with students."

      Lots more here:

      Link Preview Image
      Canvas Breach Disrupts Schools & Colleges Nationwide – Krebs on Security

      favicon

      (krebsonsecurity.com)

      #canvas #breach #shinyhunters #instructure

      jtk@infosec.exchangeJ This user is from outside of this forum
      jtk@infosec.exchangeJ This user is from outside of this forum
      jtk@infosec.exchange
      wrote last edited by
      #2

      @briankrebs Reports in the last hour that logins were working again.

      briankrebs@infosec.exchangeB 1 Reply Last reply
      0
      • jtk@infosec.exchangeJ jtk@infosec.exchange

        @briankrebs Reports in the last hour that logins were working again.

        briankrebs@infosec.exchangeB This user is from outside of this forum
        briankrebs@infosec.exchangeB This user is from outside of this forum
        briankrebs@infosec.exchange
        wrote last edited by
        #3

        @jtk I am shocked. From the story

        A source close to the investigation who was not authorized to speak to the press told KrebsOnSecurity that a number of universities have already approached the cybercrime group about paying. The same source also pointed out that the ShinyHunters data leak blog no longer lists Instructure among its current extortion victims, and that the samples of data stolen from Canvas customers were removed as well. Data extortion groups like ShinyHunters will typically only remove victims from their leak sites after receiving an extortion payment or after a victim agrees to negotiate.

        deepfryed@fosstodon.orgD mayintoronto@beige.partyM 2 Replies Last reply
        0
        • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

          @jtk I am shocked. From the story

          A source close to the investigation who was not authorized to speak to the press told KrebsOnSecurity that a number of universities have already approached the cybercrime group about paying. The same source also pointed out that the ShinyHunters data leak blog no longer lists Instructure among its current extortion victims, and that the samples of data stolen from Canvas customers were removed as well. Data extortion groups like ShinyHunters will typically only remove victims from their leak sites after receiving an extortion payment or after a victim agrees to negotiate.

          deepfryed@fosstodon.orgD This user is from outside of this forum
          deepfryed@fosstodon.orgD This user is from outside of this forum
          deepfryed@fosstodon.org
          wrote last edited by
          #4

          @briankrebs @jtk Not surprised but also not ideal. Everyone's trying to put the fire within their own area of control. Are are any further details on how they managed to do it ? The fact that they were hacked last year and again this time doesn't bode well.

          1 Reply Last reply
          0
          • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

            @jtk I am shocked. From the story

            A source close to the investigation who was not authorized to speak to the press told KrebsOnSecurity that a number of universities have already approached the cybercrime group about paying. The same source also pointed out that the ShinyHunters data leak blog no longer lists Instructure among its current extortion victims, and that the samples of data stolen from Canvas customers were removed as well. Data extortion groups like ShinyHunters will typically only remove victims from their leak sites after receiving an extortion payment or after a victim agrees to negotiate.

            mayintoronto@beige.partyM This user is from outside of this forum
            mayintoronto@beige.partyM This user is from outside of this forum
            mayintoronto@beige.party
            wrote last edited by
            #5

            @briankrebs @jtk Public institutions have since ridiculously strict rules about paying cybersecurity ransoms, no?

            1 Reply Last reply
            0
            • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

              New, from me: Canvas Breach Disrupts Schools and Colleges Nationwide

              "An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions."

              "Canvas parent firm Instructure [NYSE:INST] responded to today's defacement attacks by disabling the platform, which is used by thousands of schools, universities and businesses to manage coursework and assignments, and to communicate with students."

              Lots more here:

              Link Preview Image
              Canvas Breach Disrupts Schools & Colleges Nationwide – Krebs on Security

              favicon

              (krebsonsecurity.com)

              #canvas #breach #shinyhunters #instructure

              zl2tod@mastodon.onlineZ This user is from outside of this forum
              zl2tod@mastodon.onlineZ This user is from outside of this forum
              zl2tod@mastodon.online
              wrote last edited by
              #6

              @briankrebs

              s/nationwide/worldwide/

              Link Preview Image
              New Zealand students' details caught up in massive global university hack

              Names, email addresses, ID numbers and messages between users could all have been stolen, while students can't submit work.

              favicon

              RNZ (www.rnz.co.nz)

              zl2tod@mastodon.onlineZ 1 Reply Last reply
              0
              • briankrebs@infosec.exchangeB briankrebs@infosec.exchange

                New, from me: Canvas Breach Disrupts Schools and Colleges Nationwide

                "An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions."

                "Canvas parent firm Instructure [NYSE:INST] responded to today's defacement attacks by disabling the platform, which is used by thousands of schools, universities and businesses to manage coursework and assignments, and to communicate with students."

                Lots more here:

                Link Preview Image
                Canvas Breach Disrupts Schools & Colleges Nationwide – Krebs on Security

                favicon

                (krebsonsecurity.com)

                #canvas #breach #shinyhunters #instructure

                beachbum@mastodon.sdf.orgB This user is from outside of this forum
                beachbum@mastodon.sdf.orgB This user is from outside of this forum
                beachbum@mastodon.sdf.org
                wrote last edited by
                #7

                @briankrebs Iran?

                t2r@infosec.exchangeT 1 Reply Last reply
                0
                • zl2tod@mastodon.onlineZ zl2tod@mastodon.online

                  @briankrebs

                  s/nationwide/worldwide/

                  Link Preview Image
                  New Zealand students' details caught up in massive global university hack

                  Names, email addresses, ID numbers and messages between users could all have been stolen, while students can't submit work.

                  favicon

                  RNZ (www.rnz.co.nz)

                  zl2tod@mastodon.onlineZ This user is from outside of this forum
                  zl2tod@mastodon.onlineZ This user is from outside of this forum
                  zl2tod@mastodon.online
                  wrote last edited by
                  #8

                  @briankrebs

                  It'll be interesting to see if this ends up being a factor in the breaches:

                  "Instructure, the creators of Canvas Learning Management System, and OpenAI, the artificial intelligence research organization and developer of ChatGPT, have joined forces to present a compelling solution. Their innovative partnership shows how AI can become a normal, helpful part of everyday educational experiences, greatly improving teaching and learning processes."

                  Link Preview Image
                  Instructure And OpenAI Harness The Power Of AI To Transform Learning

                  Instructure and OpenAI partner to embed powerful AI tools within Canvas LMS, transforming learning by enabling dynamic assignments, rich feedback, and deeper insights.

                  favicon

                  Forbes (www.forbes.com)

                  1 Reply Last reply
                  0
                  • beachbum@mastodon.sdf.orgB beachbum@mastodon.sdf.org

                    @briankrebs Iran?

                    t2r@infosec.exchangeT This user is from outside of this forum
                    t2r@infosec.exchangeT This user is from outside of this forum
                    t2r@infosec.exchange
                    wrote last edited by
                    #9

                    @Beachbum @briankrebs AWS bucket “issues” have been reported for this latest breach.

                    1 Reply Last reply
                    0
                    • R relay@relay.publicsquare.global shared this topic
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • World
                    • Users
                    • Groups