Chaos erupts as cyberattack disrupts learning platform Canvas amid finals
A cyberattack by ransomware group ShinyHunters disrupted the Canvas learning platform affecting 275 million users across 8,800 schools during critical final exam periods, forcing major universities to postpone exams and exposing user data including names, email addresses, and student IDs. This incident underscores the critical vulnerability of widely-adopted SaaS platforms serving the education sector and highlights the ransomware ecosystem's ability to cause widespread operational disruption through both direct attacks and extortion tactics. IT leaders must recognize that mission-critical third-party platforms require robust incident response protocols, vendor accountability frameworks, and business continuity alternatives to mitigate similar disruptions across their organizations.
Chaos erupted at schools and colleges throughout the US on Thursday as a cyberattack disrupted online learning platform Canvas just as students were due to take final exams. Canvas parent company Instructure said that as of Friday morning, the platform was back online. Instructure said it temporarily took Canvas offline on Thursday after identifying unauthorized activity in its network. The threat actor was the same one responsible for a data breach that Instructure disclosed a week ago. Data accessed included user names, email addresses, student ID numbers, and messages exchanged on the platform. The company said it has no indication that passwords, dates of birth, government identifiers, or financial information were involved. Schools and colleges scramble A ransomware group known as ShinyHunters claimed responsibility for the breach on its dark web site. It claimed the data it took came from 275 million people associated with 8,800 schools.Read full article Comments