Widespread Cyber Attack Shuts Down Canvas Before Finals Week
Following an abrupt cyber attack that locked users out of Canvas on May 7, the online learning platform’s services have been restored.
During the attack, students were not able to access the web-based learning management system due to a far-reaching cyber hack, keeping them from seeing assignments, due dates and announcements the week before the most crucial time in the school year — finals.
On Thursday afternoon, a cyber breach “warning” pop-up appeared when users opened Canvas. The hacker group known as ShinyHunters claims full responsibility for the breach that has affected Webster among other universities across the country, including larger institutions like University of Missouri, Princeton and Harvard.
Instructure, the company behind Canvas, put the platform in “maintenance mode,” following the incident. When trying to load the service, users received a message that read, “Oops, something went wrong,” preventing them from signing back in.
To provide relief to the student body, the Office of Student Affairs released a statement on Outlook saying that it could not confirm when the software would be back up, but was “monitoring the situation.”
ShinyHunters gave Instructure until the end of day on Tuesday, May 12, before “everything is leaked,” referring to the millions of users’ data.
“If any of the schools in the affected list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement,” the ransom note from ShinyHunters said.
This is not the first time Instructure has been hacked by the cyber-criminal group that has been active since 2019.
Now that Canvas is once again available, university officials have advised students to be cautious.
“As a precaution, Webster University encourages all students, faculty and staff to remain alert for phishing emails or suspicious communications referencing Canvas, coursework, account verification, financial aid or university-related activity,” Information Services shared in a message Friday morning.
Instructure assures that Canvas is safe to use now.
“Our external forensic partner has reviewed the known indicators and found no evidence that the threat actor currently has access to the platform,” the company said. “Please don’t rely on third-party lists or social media posts naming potentially affected organizations as those lists aren’t verified. Instructure will confirm validated information through direct outreach to all affected organizations.”
Law enforcement is now involved in the case.
Instructure invites users to visit http://instructure.com/incident_update?, which will direct them to a “central source for confirmed updates, customer communications and updated FAQs about the incident.”