Canvas hackers are giving educational institutions an extra six days

The ShinyHunters hacker group has given educational institutions an extra six days to pay the ransom. The group is threatening to publish the details of 275 million Canvas users worldwide.

On Thursday evening, the hackers posted a message on various Canvas websites, including those of Dutch institutions. They claim to have hacked the programme again. VU University Amsterdam has disconnected all systems that were still connected to Canvas.

ShinyHunters

Last week it emerged that the personal data of students and lecturers had been stolen. The data comes from Canvas, an educational platform used by some 9,000 institutions worldwide. Responsibility for the attack has been claimed by ShinyHunters, a hacker group previously involved in the Odido breach.

Initially, the US-based Instructure, the creator of Canvas, was given until Wednesday to pay a ransom, otherwise all the data would be made public. However, the deadline has now been extended by six days, ShinyHunters reports on its website.

According to the group, several institutions have made contact. It does not specify which ones these are or which countries they are from. Universities and universities of applied sciences have until 12 May to negotiate to keep their data private. According to the group, Instructure itself has not yet made contact.

‘Do not pay the ransom’

In the Netherlands, seven universities and at least two universities of applied sciences use Canvas. These are the two Amsterdam universities, Erasmus University, Tilburg University, Maastricht University, the University of Twente and Eindhoven University of Technology, as well as Utrecht University of Applied Sciences and Fontys. Students and staff are asked to “be vigilant for potential phishing emails following the data breach”, writes the umbrella organisation UNL.

Following the hack on Odido, the government issued urgent advice not to pay hackers any ransom. It is quite possible that hackers will not keep their promises. ‘Paying ransom sustains the criminals’ business model,’ wrote the Minister of Justice and Security, David van Weel, at the time. (HOP, NB)

  • TU Delft does not use Canvas, but instead relies on the alternative platform Brightspace. TU Delft students who are undertaking a dual degree programme at one of the affected universities (such as Erasmus University) are advised to follow the updates issued by the relevant institution.

Comments are closed.