San Francisco State University is among the schools affected by a cyberattack on the Canvas system.

San Francisco State University is among the schools affected by a cyberattack on the Canvas system.

Lea Suzuki/S.F. Chronicle

As the global cyberattack on the Canvas learning management system entered its second day Friday, thousands of students across California found themselves locked out of the online lectures they needed to study for finals. Many could not take exams given on the platform.  Others could not submit assignments to professors or teachers.

“I think they should pay the ransom,” said Adrian Segura, 22, a UC Berkeley computer science major, referring to the threat by “ShinyHunters,” notorious hackers who posted Thursday that they would expose students’ personal information unless schools negotiated a “settlement.”

The seizure of Canvas has caused widespread disruption among millions of users, including across the University of California, California State University, the state’s 116 community colleges and K-12 schools. Education officials say the cyberattack has compromised emails, student identification numbers and internal Canvas messages — but not Social Security numbers, financial information or passwords.

Article continues below this ad

“The timing couldn’t have been worse,” said Jesse Martinez, 28, a graduate student in museum studies at San Francisco State who could not submit the documentation that was due Friday for a year-end project that his professors need to review so Martinez can complete his work before graduation — less than two weeks away.  

Canvas is the main hub for academic connections across many colleges, universities and schools. It’s how students and instructors communicate about assignments, grades, lecture schedules and office hours. And it’s where millions of students take exams. 

San Francisco Chronicle Logo

Make us a Preferred Source to get more of our news when you search.

Add Preferred Source

The status webpage for Instructure, which operates Canvas, said Friday that “Canvas is now available for most users” but added that “Canvas Beta” and “Canvas Test” were still in “maintenance.”

By Friday afternoon, Canvas appeared to be slowly coming back online across California’s schools, colleges and universities. 

Article continues below this ad

CSU said its Canvas services were back online but that “in an abundance of caution, CSU has not yet fully reintegrated our campus systems or data connections with Canvas.”

The statewide community college system was taking a similarly slow approach, and technology executive Jory Hadsell said the state chancellor’s office was alerting colleges to “remain alert to potential phishing or scam attempts.” 

In its Canvas update, UC called the breach “contained and remediated” but said the university was making “risk-based decisions” about re-opening Canvas. 

“We understand the disruption this incident has caused for students, faculty and staff,” said the post that included links to each campus’ messaging about the hack. By 2 p.m., UC Berkeley’s notice said Canvas “has largely been restored and final exams will proceed as scheduled.”

Neither UC nor CSU responded when asked if they had paid the requested ransom.

Article continues below this ad

With finals scheduled for this week and next week across campuses, students and faculty said the disruption has been significant. 

The advice for instructors was to devise alternative ways of communicating with students, but one UC Berkeley instructor said that was easier said than done. This is “Dead Week” at UC Berkeley, when classes are suspended so students can spend their time cramming for next week’s exams.

“We’re going to create a Google Drive (to share study materials) but I have no way to mass-email it to students without Canvas,” said Sara, a graduate student instructor who asked that her last name not be used so she could speak freely about her students.

“I feel bad for them,” she said, noting that the drive contains reading materials and lecture slides for social science classes. “I’m going to email as many as I can and tell them to share it with their friends. The shutdown makes it very hard for them to study.”

UC Berkeley microbiology student Chiara Vinzoni said: “With this being the week before the finals I think it’s fair to say everyone is panicking, myself included.  The timing of this all is extremely frustrating.”

Article continues below this ad

Instructure first alerted schools to a problem on May 1, UC Berkeley officials said. And while some, including the California Community College system, initially believed the cyber intrusion to be minimal and easily contained, by Thursday the attack had become entrenched.

That’s when students who logged in to Canvas could not get back into the system after refreshing. Many found this message splayed across their screens:

“ShinyHunters has breached Instructure (again). …If any of the schools in the affected list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately … to negotiate a settlement.” The message gave Instructure a deadline of May 12 to contact the group. 

To Segura, the UC Berkeley computer science major, the Canvas hacking “is pretty stressful” not because he can’t access assignments in two English classes, but because he fears that his personal information will be leaked.

Segura is so concerned about security — even his last name means “secure” in Spanish — that he said he types a fake date of birth into computers when asked, unless it’s for a medical issue or is legally required, he said, such as his university registration.

Article continues below this ad

“ShinyHunters is pretty notorious because they have a lot of high-target attacks,” he said. “So I’m way more worried because my actual information is all in Canvas. Now they have information that makes me susceptible to phishing schemes. Or let’s say my housemate gets hacked and they send me an email. It would be a lot harder to tell it wasn’t from him.”

Cliff Steinhauer, director of information security at the nonprofit advocacy group National Cybersecurity Alliance, said the Canvas breach highlights the danger of having schools depend heavily on centralized platforms for their critical operations.

“When a system used by thousands of institutions goes down during finals season, it demonstrates that cybersecurity incidents can quickly become large-scale operational disruptions, not just isolated IT problems,” he said.

“Even if highly sensitive financial information was not exposed, educational records, communications, and identity data can still be valuable to cybercriminals for phishing, impersonation, and future attacks.

Privacy experts recommend that students and their families take these steps to protect personal privacy.

• Change your password. Change the password you used for Canvas, and if you used that same password anywhere else, change that, too. Add multifactor (sometimes called two factor) authentication anywhere that offers it for an added layer of protection.

• Be extra wary about any communication you receive that includes your personal details. Scammers like to have so-called “contextual” information like the name of your child’s teacher because it allows them to fine-tune their messages to seem more authentic. Any email, text, letter or phone call you receive that mentions anything about your child or their school, instructor or class should be met with additional scrutiny. Be on the lookout for fake fundraisers, suspicious-looking links to websites for events, or requests to send money for any reason. Call the school, college or university directly to verify requests.

• Freeze your credit and your child’s credit. It’s never a bad time to freeze your credit, a process that takes approximately 15 to 20 minutes and only a couple of minutes to undo when you need to open your credit file. You can and should freeze it on behalf of minor children. Here’s your full guide.