CRBC News
Security

Canvas Outage Tied to Cyberattack Disrupts College Finals; ShinyHunters Claims Credit

Canvas Outage Tied to Cyberattack Disrupts College Finals; ShinyHunters Claims Credit
FILE - People take photos near a John Harvard statue, left, on the Harvard University campus, Jan. 2, 2024, in Cambridge, Mass. (AP Photo/Steven Senne, File)

Canvas, the learning platform used by many colleges for exams, lectures and grades, suffered an outage tied to a cyberattack during finals week. Instructure said service was restored for most users, while some schools kept Canvas restricted as they assessed security risks. The hacking group ShinyHunters claimed responsibility and threatened to release data from nearly 9,000 schools and 275 million people if ransom demands were not met. Instructure reported that student IDs, emails, names and messages may have been exposed, but found no evidence that passwords, birth dates, government IDs or financial data were accessed.

Colleges and universities across the United States experienced major disruption during finals week after Canvas, the widely used learning-management platform, went offline in an incident officials linked to a cyberattack.

By late Thursday, Instructure — the company that owns Canvas — reported that the platform was available again for most users, though several institutions continued to restrict access as a precaution while they reviewed potential security risks.

Who Claims Responsibility

Cybersecurity researchers said the hacking group ShinyHunters claimed responsibility for the breach. According to Luke Connolly, a threat analyst at Emsisoft, ShinyHunters initially listed Instructure and Canvas among its targets but by Friday those names no longer appeared on the group's public target page.

Scope Of The Threat And Ransom Demand

Earlier in the week, ShinyHunters warned that data from nearly 9,000 schools and roughly 275 million individuals could be exposed unless institutions paid a ransom by a May 6 deadline. The group later extended that deadline, which indicated some schools had engaged in negotiations.

Data Impacts Reported

Instructure's chief information security officer, Steve Proud, said the breach appears to have involved student ID numbers, email addresses, names and messages stored on Canvas. He added that the company had not found evidence that passwords, dates of birth, government identification numbers or financial information were compromised.

Academic Disruptions

The outage struck at a high-stress moment for students and faculty: Canvas is used as a digital gradebook, a repository for lecture recordings and course documents, a discussion forum, a messaging hub and a delivery system for quizzes and exams. Several institutions adjusted their final-exam schedules in response.

Examples include the University of Massachusetts Dartmouth, which postponed exams scheduled for Friday and Saturday to give students time to review unavailable materials. The University of Illinois postponed all exams slated for Friday through Sunday for every class, regardless of whether those courses used Canvas. Montgomery County Public Schools in Maryland continued to limit Canvas access while investigating potential vulnerabilities.

Why Schools Are Targets

Educational institutions hold large amounts of personally identifiable information about students, faculty and staff, making them frequent targets for ransomware operators and other cybercriminals. Attackers sometimes target school districts directly and sometimes target third-party vendors such as Canvas or PowerSchool that schools rely on for scheduling, course management and exams.

Note: The Associated Press reported this story; AP is solely responsible for its content.

Help us improve.

Related Articles

Trending