UC Berkeley and Berkeley City College are among the many schools across the country recovering from an outage that knocked down Canvas, an online platform that manages exams, course notes, lecture videos and grades. The disruption tied to a cyberattack hit in the middle of finals period for many colleges, a high-stress time when students and instructors rely heavily on the platform.
By late Thursday, Instructure, the parent company of Canvas, said the platform was available again to most users.
The hacking group ShinyHunters claimed responsibility for the breach, said Luke Connolly, a threat analyst at the cybersecurity firm Emsisoft. On Friday, Instructure and Canvas no longer appeared on a site where ShinyHunters lists its targets.
Some schools, however, have continued to block students and teachers from accessing Canvas, citing an abundance of caution while assessing security threats.
“UC Berkeley is currently conducting security assurance and integrity checks before re-enabling full access,” the university said in a message last updated Friday morning.
Officials at the Peralta Community College District, which includes Berkeley City College, warned students not to click on any links related to Canvas or the hacking message until they are notified that Canvas is operational.
San Francisco State University and Stanford are also among the schools affected in the Bay Area.
Here’s what to know about the outage.
What is Canvas?
Schools and universities use Canvas to manage nearly all aspects of instruction. The platform acts as a gradebook, a hub for digital lectures and course materials, a discussion board for classroom projects, and a messaging platform between students and instructors.
Some courses also give quizzes and exams on the platform, or use it as a portal where final projects and papers are submitted on deadline.
Who is ShinyHunters?
ShinyHunters is a loose association of teenage and young adult hackers in the U.S. and the United Kingdom who have been linked to other large-scale cyberattacks, including one on Ticketmaster, Connolly said. On the page listing their targets, the group describes itself as “rooting your systems since ‘19,” using a term for accessing a computer system’s deepest layer.
Earlier this week, ShinyHunters said that nearly 9,000 schools and 275 million individuals’ data could be leaked if schools did not pay the ransom by a deadline of May 6. The group then extended the deadline, indicating some schools had engaged with them to negotiate.
In a statement posted to ShinyHunters’ ransomware site, the group said it would not be commenting on the incident.
Schools and universities, rich in personally-identifiable information on students, teachers and employees, have become prime targets for criminal hackers in ransomware attacks. Targets can be individual districts, like the Minneapolis Public Schools or Los Angeles Unified School District, or external vendor platforms like Canvas or PowerSchool that education systems increasingly rely on to manage schedules, courses and exams.
The impact on students
The data breach appeared to involve student ID numbers, email addresses, names and messages on the Canvas platform, Instructure’s chief information security officer, Steve Proud, said in an update shared Saturday. He said the company had not found evidence that passwords, dates of birth, government identification or financial information were compromised.
Though most schools seem to have restored access to Canvas, the disruptions to finals period are likely to ripple throughout the week.
This story was produced by the Associated Press. KQED contributed reporting. Featured photo: Ximena Natera, Berkeleyside/CatchLight Local
“*” indicates required fields