home.social

#instructure — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #instructure, aggregated by home.social.

fetched live
  1. GovTech reports on the ITRC's H1 report:

    "[ITRC]found that 1,029 data compromises generated 471 million breach notices in the first half of the year, with one incident — the breach involving Instructure’s Canvas platform — accounting for 275 million of those notices, or about 58 percent of the total."

    govtech.com/security/instructu

    Direct link to ITRC report:
    idtheftcenter.org/post/mega-br

    #databreach #cybersecurity #supplychain #Canvas #Instructure #EdTech

    @douglevin @funnymonkey

  2. GovTech reports on the ITRC's H1 report:

    "[ITRC]found that 1,029 data compromises generated 471 million breach notices in the first half of the year, with one incident — the breach involving Instructure’s Canvas platform — accounting for 275 million of those notices, or about 58 percent of the total."

    govtech.com/security/instructu

    Direct link to ITRC report:
    idtheftcenter.org/post/mega-br

    #databreach #cybersecurity #supplychain #Canvas #Instructure #EdTech

    @douglevin @funnymonkey

  3. 𝐒𝐢𝐧𝐜𝐞 𝐖𝐡𝐞𝐧 𝐃𝐢𝐝 𝐀𝐬𝐤𝐢𝐧𝐠 𝐟𝐨𝐫 𝐄𝐯𝐢𝐝𝐞𝐧𝐜𝐞 𝐁𝐞𝐜𝐨𝐦𝐞 “𝐃𝐞𝐟𝐞𝐧𝐝𝐢𝐧𝐠 𝐂𝐫𝐢𝐦𝐢𝐧𝐚𝐥𝐬”?

    Dissent responded harshly to these accusations, firmly rejecting any insinuation of collusion with criminal groups. The journalist pointed out that every time she asks for evidence to support certain claims, she is labeled “criminal-friendly” or accused of being a mouthpiece for cybercriminals, simply for refusing to uncritically accept statements lacking public verification.

    suspectfile.com/since-when-did

    #Canvas #Data_Breach #Instructure #Navigate360 #Ransom #ShinyHunters

  4. 𝐒𝐢𝐧𝐜𝐞 𝐖𝐡𝐞𝐧 𝐃𝐢𝐝 𝐀𝐬𝐤𝐢𝐧𝐠 𝐟𝐨𝐫 𝐄𝐯𝐢𝐝𝐞𝐧𝐜𝐞 𝐁𝐞𝐜𝐨𝐦𝐞 “𝐃𝐞𝐟𝐞𝐧𝐝𝐢𝐧𝐠 𝐂𝐫𝐢𝐦𝐢𝐧𝐚𝐥𝐬”?

    Dissent responded harshly to these accusations, firmly rejecting any insinuation of collusion with criminal groups. The journalist pointed out that every time she asks for evidence to support certain claims, she is labeled “criminal-friendly” or accused of being a mouthpiece for cybercriminals, simply for refusing to uncritically accept statements lacking public verification.

    suspectfile.com/since-when-did

    #Canvas #Data_Breach #Instructure #Navigate360 #Ransom #ShinyHunters

  5. NEW by me:

    Another detail emerges about Instructure's agreement with ShinyHunters; Debate continues about whether to pay:

    databreaches.net/2026/05/16/an

    Cybersecurity experts make claims about ShinyHunters to journalists, but where is the evidence to support their claims? Journalists shouldn't just quote experts -- ask them the basis for their claims. How much evidence do they actually have to support their assertions?

    #hackandleak #databreach #Instructure #ShinyHunters #ransom #journalism

    @amvinfe @masek @euroinfosec

  6. NEW by me:

    Another detail emerges about Instructure's agreement with ShinyHunters; Debate continues about whether to pay:

    databreaches.net/2026/05/16/an

    Cybersecurity experts make claims about ShinyHunters to journalists, but where is the evidence to support their claims? Journalists shouldn't just quote experts -- ask them the basis for their claims. How much evidence do they actually have to support their assertions?

    #hackandleak #databreach #Instructure #ShinyHunters #ransom #journalism

    @amvinfe @masek @euroinfosec

  7. Instructure has reached an agreement with the #ShinyHunters group to return and destroy stolen Canvas data, protecting millions of student records worldwide from being publicly leaked.

    Read: hackread.com/instructure-shiny

    #CyberSecurity #DataBreach #Instructure #Canvas #Privacy

  8. Instructure has reached an agreement with the #ShinyHunters group to return and destroy stolen Canvas data, protecting millions of student records worldwide from being publicly leaked.

    Read: hackread.com/instructure-shiny

    #CyberSecurity #DataBreach #Instructure #Canvas #Privacy

  9. 𝐑𝐚𝐧𝐬𝐨𝐦𝐰𝐚𝐫𝐞, 𝐓𝐫𝐚𝐧𝐬𝐩𝐚𝐫𝐞𝐧𝐜𝐲, 𝐚𝐧𝐝 𝐈𝐧𝐯𝐢𝐬𝐢𝐛𝐥𝐞 𝐕𝐢𝐜𝐭𝐢𝐦𝐬: 𝐃𝐢𝐬𝐬𝐞𝐧𝐭 𝐑𝐞𝐬𝐩𝐨𝐧𝐝𝐬 𝐭𝐨 𝐭𝐡𝐞 𝐈𝐧𝐬𝐭𝐫𝐮𝐜𝐭𝐮𝐫𝐞 𝐂𝐚𝐬𝐞

    A recent article published by DataBreaches.net by journalist Dissent addresses one of the most controversial issues in modern cybersecurity: the payment of ransoms following a cyberattack and the consequences such decisions can have not only on the companies involved, but also on the individuals whose data has been compromised.

    suspectfile.com/ransomware-tra

    #Canvas #Data_Breach #Instructure #Navigate360 #Ransom #Ransomware #ShinyHunters

  10. 𝐑𝐚𝐧𝐬𝐨𝐦𝐰𝐚𝐫𝐞, 𝐓𝐫𝐚𝐧𝐬𝐩𝐚𝐫𝐞𝐧𝐜𝐲, 𝐚𝐧𝐝 𝐈𝐧𝐯𝐢𝐬𝐢𝐛𝐥𝐞 𝐕𝐢𝐜𝐭𝐢𝐦𝐬: 𝐃𝐢𝐬𝐬𝐞𝐧𝐭 𝐑𝐞𝐬𝐩𝐨𝐧𝐝𝐬 𝐭𝐨 𝐭𝐡𝐞 𝐈𝐧𝐬𝐭𝐫𝐮𝐜𝐭𝐮𝐫𝐞 𝐂𝐚𝐬𝐞

    A recent article published by DataBreaches.net by journalist Dissent addresses one of the most controversial issues in modern cybersecurity: the payment of ransoms following a cyberattack and the consequences such decisions can have not only on the companies involved, but also on the individuals whose data has been compromised.

    suspectfile.com/ransomware-tra

    #Canvas #Data_Breach #Instructure #Navigate360 #Ransom #Ransomware #ShinyHunters

  11. So, #Instructure decided their best course of action was to fork over some cash to the digital bullies instead of dealing with their own security mess. 🎩💰 Meanwhile, the article obsesses over institutional access like it's a VIP club nobody asked for. 🎟️🤡
    insidehighered.com/news/tech-i #DigitalBullying #SecurityIssues #InstitutionalAccess #VIPClub #HackerNews #ngated

  12. So, #Instructure decided their best course of action was to fork over some cash to the digital bullies instead of dealing with their own security mess. 🎩💰 Meanwhile, the article obsesses over institutional access like it's a VIP club nobody asked for. 🎟️🤡
    insidehighered.com/news/tech-i #DigitalBullying #SecurityIssues #InstitutionalAccess #VIPClub #HackerNews #ngated

  13. From #CheckPoint Research:

    Canvas Data Breach

    #Instructure, the US education technology company behind the #Canvas learning platform, has confirmed a major data breach affecting its cloud-hosted environment. Exposed data reportedly includes student and staff records and private messages, while #ShinyHunters escalated the attack by defacing hundreds of school login portals with ransom messages.

    research.checkpoint.com/2026/1

  14. From #CheckPoint Research:

    Canvas Data Breach

    #Instructure, the US education technology company behind the #Canvas learning platform, has confirmed a major data breach affecting its cloud-hosted environment. Exposed data reportedly includes student and staff records and private messages, while #ShinyHunters escalated the attack by defacing hundreds of school login portals with ransom messages.

    research.checkpoint.com/2026/1

  15. Hackers Exploit Canvas Flaw to Deface Instructure Portals

    In a shocking breach, hackers exploited a flaw in Canvas to infiltrate Instructure portals, making off with a staggering 3.6 terabytes of data and putting 8,809 educational organizations at risk. The attackers, known as ShinyHunters, claimed to have stolen 275 million records in a brazen heist.

    osintsights.com/hackers-exploi

    #DataBreach #Instructure #Shinyhunters #Canvas #EducationalSector

  16. Restablecen el sistema Canvas tras un ciberataque global que afectó a miles de instituciones

    Decenas de miles de estudiantes recuperaron el acceso a la plataforma de aprendizaje Canvas luego de que un ataque del grupo ShinyHunters interrumpiera las actividades en 9,000 escuelas y universidades en plena temporada de exámenes finales (Fuente SecurityWeek).

    La plataforma Canvas, propiedad de Instructure, ha vuelto a estar operativa tras sufrir uno de los mayores ciberataques registrados en el sector educativo. El incidente, que comenzó a detectarse a finales de abril pero escaló drásticamente el 7 de mayo, obligó a la compañía a desconectar el sistema a nivel mundial para contener una intrusión que permitió a los atacantes alterar las páginas de inicio de los usuarios con mensajes de extorsión y amenazas de filtración de datos.

    Según las investigaciones, el grupo de hacking ShinyHunters explotó una vulnerabilidad vinculada a las cuentas de tipo «Free-For-Teacher» para acceder a unos 3.6 terabytes de información. Los datos comprometidos incluyen nombres, correos electrónicos, números de identificación estudiantil y millones de mensajes privados entre alumnos y profesores. Aunque Instructure asegura que no hay pruebas de que contraseñas o datos financieros hayan sido robados, instituciones de renombre —incluyendo todas las de la Ivy League y universidades en Canadá, Europa y Australia— han emitido alertas ante el riesgo de campañas de phishing altamente dirigidas que utilicen el contexto académico real de los usuarios.

    El impacto del apagón fue crítico, coincidiendo con el cierre de semestre y exámenes finales en Estados Unidos y otras regiones, lo que forzó a reprogramar evaluaciones y extender plazos de entrega. Aunque el servicio se ha restablecido para la mayoría, el grupo atacante ha fijado el 12 de mayo como fecha límite para el pago de un rescate antes de filtrar la información robada, manteniendo en vilo a la comunidad educativa global sobre la privacidad de sus registros personales.

    #arielmcorg #canvas #ciberataque #educacion #hacking #instructure #PORTADA #SeguridadInformatica #shinyhunters #tecnologia
  17. Hello #parents — I imagine most of you have received some kind of communication from your kids' schools about the #Instructure / #Canvas data breach. I'm collecting examples of how schools have communicated the issue to parents and students (and *if* they've communicated directly to students).

    Shoot me an email if you have anything you could share: [email protected]

  18. Hello #parents — I imagine most of you have received some kind of communication from your kids' schools about the #Instructure / #Canvas data breach. I'm collecting examples of how schools have communicated the issue to parents and students (and *if* they've communicated directly to students).

    Shoot me an email if you have anything you could share: [email protected]

  19. I realize it may never be public, but I imagine a full Monday morning morbidity on this breach would be fascinating.

    On the other hand, Occam's razor says it was either ../ or a password on a post it...

    #Instructure
    #Canvas

  20. I realize it may never be public, but I imagine a full Monday morning morbidity on this breach would be fascinating.

    On the other hand, Occam's razor says it was either ../ or a password on a post it...

    #Instructure
    #Canvas

  21. If anyone is bored this weekend - and wants to help the edu sector out in the wake of the Canvas LMS attacks - take a gander at the recently implemented and forthcoming security patches in Canvas LMS and see what you might glean. Instructure - the company that was attacked - has provided scant technical details on how initial access and exfil happened - and as a result customers (schools and universities) are left unsure as to how to trust the software or what mitigations to put in place.

    Instructure has said the attack was "carried out...by exploiting an issue related to our Free-For-Teacher accounts" instructure.com/incident_update

    Precautionary UX changes made by Instructure in response community.instructure.com/en/d

    Instructure Enforcements, Deprecations, and Breaking Changes (which contain some upcoming security related changes): community.instructure.com/en/k

    May be other threads to pull; this is being actively worked on by many.

    Thank you!

    #edtech #Instructure #Canvas cc/ @funnymonkey @PogoWasRight

  22. "We conclude that institutions of higher education are currently ill-equipped to protect students and faculty required to use the #canvas #Instructure #LMS from data harvesting or exploitation." #edtech researchgate.net/publication/3

  23. "We conclude that institutions of higher education are currently ill-equipped to protect students and faculty required to use the #canvas #Instructure #LMS from data harvesting or exploitation." #edtech researchgate.net/publication/3

  24. ShinyHunters Breach Disrupts Canvas Education Platform Nationwide

    A massive cyberattack by ShinyHunters has disrupted the Canvas Education Platform nationwide, with hackers defacing login pages and holding sensitive data on 275 million students and faculty hostage. The breach forced Instructure to pull Canvas offline, leaving students and faculty in the dark.

    osintsights.com/shinyhunters-b

    #Shinyhunters #Ransomware #EducationSector #Canvas #Instructure

  25. “Instructure said Wednesday that Canvas was fully operational… on Friday, the company discovered that the "unauthorized actor" … made changes to the pages that appeared when some students and teachers were logged in… immediately took Canvas offline… Canvas is now fully back online”.

    Except #Canvas at #UofT is actually “unavailable until further notice” 🤷🏼‍♂️

    #instructure #hack
    cbc.ca/news/canada/toronto/ont

  26. #Cyberattack hits #Canvas system used by thousands of schools as #finals loom

    By HEATHER HOLLINGSWORTH
    Updated 11:19 PM EDT, May 7, 2026

    Excerpt: "Connolly said the Canvas attack is strikingly similar to a breach at #PowerSchool, which also offers learning management tools [#LMS]. In that case a Massachusetts college student was charged.

    "Connolly described #ShinyHunters as a loose affiliation of teenagers and young adults based in the U.S. and the United Kingdom. The group also has been tied to a other attacks, including one aimed at #LiveNation’s #Ticketmaster subsidiary."

    Read more:
    apnews.com/article/cyberattack

    #CanvasLMS #Instructure #CanvasPlatform #Cyberattack #CanvasSoftware #Education #Technology #Databreach

  27. An email sent to students by one college impacted by the Canvas outage claims the college's Office of Information Technology took down their Canvas instance yesterday "as a security precaution".

    Students and teachers at some locations are able to access Canvas, but one professor told me Canvas at their campus is still offline.

    Pro-Iran group 313 Team claimed responsibility for the attack yesterday, though in statements to the press, Canvas owner Instructure has said they took down Canvas in response to an earlier compromise by Shiny Hunters.

    The actual cause of the outage remains unclear, with both sides offering conflicting statements.

    #CanvasDown #Instructure #ShinyHunters #Iran

  28. A massive ShinyHunters attack has compromised Canvas login portals for 15,000 institutions, including top universities like Harvard and Oxford, exfiltrating 3.65 terabytes of student and faculty data. This incident, alongside a concurrent supply chain attack on Vimeo, exposes critical flaws in EdTech security and third-party vendor trust, raising urgent questions about data protection.

    tpp.blog/1oujkrv

    #cybersecurity #canvas #instructure

    🤖 This post was AI-generated.

  29. New, from me: Canvas Breach Disrupts Schools and Colleges Nationwide

    "An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions."

    "Canvas parent firm Instructure responded to today's defacement attacks by disabling the platform, which is used by thousands of schools, universities and businesses to manage coursework and assignments, and to communicate with students."

    Lots more here:

    krebsonsecurity.com/2026/05/ca

    #canvas #breach #shinyhunters #instructure

  30. I've seen questions about the #instructure #canvas leak, to the effect of "why's the data so dangerous if there's nothing financial in it?"

    There are identifiers, for one thing.

    But I think the real threat is... look, students send instructors some really heavy and confidential stuff in Canvas messaging sometimes. Identity stuff. Health stuff. Family stuff. Relationship stuff. Even crime stuff.

    I really am relieved that I direct students to email. I feel horrible for what could happen.