Instructure & JCCC React To Canvas Hack

Pop-up message on Canvas log-in page.

(Photo from the Canvas log-in page)


JCCC student Olivia Cramer sat down to finish an assignment due at midnight on the evening of May 7, only to find that Canvas was down. She was upset when her brother informed her that it was not functioning due to a hack.

“I wrote a very colorful text to my family that day,” Cramer said. “I was so pissed about it.” The text was confirmed to be too colorful for print.

On May 12, Cramer said she was still unsure if she would be able to turn in the assignment.

Canvas, a learning management system by tech company Instructure, is contracted by 40% of North American higher-ed institutions and used by tens of millions of students worldwide.

With finals looming, many of these students attempted to log on, only to see a ransom note from the hacking group ShinyHunters. The note set a deadline of May 12 for Instructure to negotiate a settlement before the data of faculty and students was leaked.

In a statement published on May 11, Instructure apologized for the incident and said that they had reached an agreement with ShinyHunters.

The statement explains that the company “received digital confirmation of data destruction” through shred logs. Instructure claims that Canvas users would not be extorted or need to engage with the hackers.

Instructure did not reveal how much was paid in ransom to the hackers.

JCCC Chief Information Officer Rob Caffey and his co-workers were the primary incident response team. They became aware, by multiple channels, of an initial attack on April 29, then again on May 7 when the system was down.

“We were really concerned that it was going to be offline for finals,” said Caffey.

Caffey said the data included names, student ID numbers and email addresses, but not passwords or federal IDs.

“The team was doing what they could to address the issue and were focused on keeping students’ data safe,” said Caffey. “We’ve got a really good team that works really hard.”

Despite Caffey and his team’s hard work, since a third party was the target, they were mostly dependent on Instructure to resolve the issue.

 

Gurbhushan Singh, Associate VP of Academics, says that even though Canvas was back up and running quickly, JCCC has received reports of residual issues from students and faculty.

“We are asking faculty and staff to show flexibility as we navigate these challenges together and work to end the semester positively,” said Singh.

With advancements in AI, ransomware and cybercrime will likely be more frequent, complex and convincing. With this in mind, Caffey recommends that students take online safety precautions seriously.

“Watch for fake emails about this breach,” Caffey said. “Turn on multi-factor authentication. Use a different password for every account. Slow down on anything ‘urgent.’ Go to the source, not the link. Don’t pay extortion messages. Ask for help when you’re not sure.”

If you have noticed any suspicious activity linked with your student account since the hack, you can contact the Technical Support Center by phone at (913)-469-7700, email at [email protected] or walk-in at RC 271.

Author


Posted

in

Tags:

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

About Us