{"id":654607,"date":"2026-05-07T02:47:10","date_gmt":"2026-05-07T02:47:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/654607\/"},"modified":"2026-05-07T02:47:10","modified_gmt":"2026-05-07T02:47:10","slug":"canvas-data-breach-leaves-education-providers-scrambling-as-student-data-compromised","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/654607\/","title":{"rendered":"Canvas data breach leaves education providers scrambling as student data compromised"},"content":{"rendered":"<p class=\"paragraph_paragraph___QITb\">Education institutions around the country are scrambling to respond to a global data breach that has affected Australian universities, TAFE and public schools in at least two states.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Almost 9,000 institutions worldwide are clients of the cloud-based Canvas learning management system, developed by American company Instructure, which was subject to the hack.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Among providers confirmed to have been affected are state schools in Queensland and Tasmania, universities in NSW and South Australia and TAFE in Tasmania.\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">In a post over the weekend on its <a class=\"Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/status.instructure.com\/\" data-component=\"Link\" rel=\"nofollow noopener\" target=\"_blank\">status page for customers<\/a>, Instructure said it had &#8220;recently experienced a cybersecurity incident perpetrated by a criminal threat actor&#8221;.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;We are working quickly to understand the extent of the incident and actively taking steps to minimise its impact,&#8221; wrote Instructure chief information security officer Steve Proud.<\/p>\n<p class=\"paragraph_paragraph___QITb\">This morning Mr Proud gave an update, saying the company believed it had &#8220;contained&#8221; the security incident.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;While we continue actively investigating, thus far, indications are that the information involved consists of certain identifying information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as messages among users,&#8221; he wrote.<\/p>\n<p>&#8220;At this time, we have found no evidence that passwords, dates of birth, government identifiers, or financial information were involved. If that changes, we will notify any impacted institutions.&#8221;<\/p>\n<p class=\"paragraph_paragraph___QITb\">The federal government&#8217;s National Office of Cyber Security is coordinating a response.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Cyber security industry website BleepingComputer said notorious hacking group ShinyHunters had claimed responsibility for the breach.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The group recently also claimed responsibility for hacking developer Rockstar \u2014 the makers of one of the largest video game franchises in the world, Grand Theft Auto. Data from the that breach was released online after a ransom was not paid.<\/p>\n<p class=\"paragraph_paragraph___QITb\">It is understood the compromised Canvas data has not been publicly released at this stage.<\/p>\n<p>State schools, universities and TAFE affected<\/p>\n<p class=\"paragraph_paragraph___QITb\">Tens of thousands of Queensland students and teachers studying or working at Queensland state schools since 2020 were among those affected, according to the state government.<\/p>\n<p class=\"paragraph_paragraph___QITb\">In a statement, education minister John-Paul Langbroek said early advice suggested more than 200 million people could be impacted worldwide by the data breach, across more than 9,000 schools, universities and other institutions, and that principals would contact affected families.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Instructure delivered the Queensland Education Department&#8217;s online learning platform, QLearn.<\/p>\n<p><img decoding=\"async\" alt=\"Man in blue suit.\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/05\/ca4ee5dcc53471897170a398c35ebf72.jpeg\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">John-Paul Langbroek says tens of thousands of Queensland students have been affected by the data breach. (ABC Gold Coast: Dominic Cansdale)<\/p>\n<p class=\"paragraph_paragraph___QITb\">Mr Langbroek said his department was providing &#8220;priority support&#8221; to families known to child safety authorities, or those with a known history of domestic and family violence, and that school principals were in the process of contacting families and teachers about the breach.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Tasmania&#8217;s Department of Education also confirmed state schools used the Canvas platform to track learning between staff and students and that it had been notified about the breach.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Investigations commenced immediately and are ongoing. At this stage, while DECYP has been identified as being impacted by the cyber security incident, the specific impact of the incident is subject to further investigation by Instructure,&#8221; it said in a statement.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Tasmanian provider TasTafe yesterday revealed <a class=\"Link_link__kR0xA Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2026-05-06\/australian-educational-facilities-impacted-by-canvas-hack\/106650094\" data-component=\"Link\" data-uri=\"coremedia:\/\/article\/106650094\" rel=\"nofollow noopener\" target=\"_blank\">some of its students had been compromised following a cybersecurity attack<\/a> on the Canvas learning management system, developed by Instructure, while other education institutions were investigating the impacts.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Speaking on 936 ABC Hobart Mornings, TasTAFE chief executive Norman Baker said he had been told hackers were demanding a ransom, and that some of the data stolen by the hackers was from chats between students and teachers.<\/p>\n<p class=\"paragraph_paragraph___QITb\">A New South Wales Department of Education spokesperson said they were working to determine if any NSW schools had been impacted.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Schools using the departmental sign on do not have their passwords stored with Canvas, so there is no risk of credential exposure in those cases,&#8221; they said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">A University of Melbourne spokeswoman said they had been notified of the cyber incident.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;We take the protection and management of personal information seriously and are working with the vendor to confirm and respond to any impacts,&#8221; they said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">A spokesperson for Flinders University in Adelaide said it had been informed that student and staff data within the Canvas platform &#8220;may have been impacted&#8221;.<\/p>\n","protected":false},"excerpt":{"rendered":"Education institutions around the country are scrambling to respond to a global data breach that has affected Australian&hellip;\n","protected":false},"author":2,"featured_media":653037,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[64,63,99,14279,8886,15878],"class_list":["post-654607","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-au","tag-australia","tag-business","tag-data-breach","tag-hacking","tag-queensland-government"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/654607","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=654607"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/654607\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/653037"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=654607"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=654607"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=654607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}