Skip to main content

Global Canvas LMS Data Breach

Alert

Background

 

A major cybersecurity incident has impacted Canvas Learning Management System (Canvas LMS), affecting thousands of educational institutions worldwide including institutions in Brunei Darussalam. The hacking group ShinyHunters has claimed responsibility for exfiltrating approximately 3.65TB of data, affecting nearly 9,000 educational institutions worldwide.


The data exfiltrated includes full names, email addresses, and student ID numbers, as well as institutional account information. Additionally, more sensitive communications were exposed, specifically private Canvas inbox messages and course-related communication data.

 

Impact

 

  • Unauthorized access to public-facing LMS application via vulnerabilities in account management.
  • Data exfiltration enabled the exposure of personally identifiable information (PII), including names and email addresses.
  • Exfiltration of internal communication through Canvas inbox.
  • Can be used to craft high-fidelity spear-phishing campaigns.

 

Recommendations

 

  • Reset Canvas passwords immediately through the official Instructure Canvas portal or your institution's official login page.
  • Enable Multi-Factor Authentication (MFA) on all accounts associated with Canvas, including Microsoft 365, Google Workspace, and institutional accounts.
  • Do not click links in emails to log into Canvas. Always type the official URL of your institution directly into your browser.
  • Monitor private messages sent through Canvas, as they may have been leaked in this incident.

 

References