{"id":258133,"date":"2026-08-03T06:15:20","date_gmt":"2026-08-03T06:15:20","guid":{"rendered":"https:\/\/www.newsbeep.com\/us-pa\/258133\/"},"modified":"2026-08-03T06:15:20","modified_gmt":"2026-08-03T06:15:20","slug":"pitt-digital-says-preventing-hacks-complex-but-there-are-areas-to-scrutinize-university-times","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us-pa\/258133\/","title":{"rendered":"Pitt Digital says preventing hacks complex, but there are areas to scrutinize | University Times"},"content":{"rendered":"<p>\n\tBy MARTY LEVINE<\/p>\n<p>\n\tPitt Digital has already taken a new step to prevent future Canvas hacks, such as the spring incident that targeted more than 100 organizations \u2014 most of them universities \u2014 and caused Instructure, the parent company of the Canvas learning management system, to pay the hacking group \u201cShinyHunters\u201d a ransom to keep the stolen data out of even worse hands.<\/p>\n<p>\n\tBut fully preventing such future hacks of the software companies so many universities use (such the more recent PeopleSoft breach, also by ShinyHunters, that did not compromise any data or continue further, according to Pitt\u2019s PeopleSoft provider) is a complex issue, said John Duska, Pitt Digital\u2019s chief information security officer.<\/p>\n<p>\n\tSince those two incidents, Duska said, \u201cPitt Digital turned off students\u2019 ability to create access keys (called API tokens) that let outside apps or scripts connect directly to a Canvas account. These keys are a common target for bad actors because they can be used to pull data without needing a password, so removing this access for students reduces one more way a Canvas account could be exploited.<\/p>\n<p>\n\t\u201cThis kind of incident tends to push institutions to focus on three things,\u201d Duska added: \u201cMaking sure only the right people and systems have access to sensitive data (the access-key change is one example); more closely scrutinizing the outside companies whose software they rely on; and improving their ability to detect problems quickly when something does go wrong.\u201d<\/p>\n<p>\n\tAsked for further plans to increase local security, Duska could only reply: \u201cWe generally avoid detailing specific security strategies publicly, since doing so could give adversaries useful information about how to work around them. But these are the general areas institutions like ours continue to invest in.\u201d<\/p>\n<p>\n\tAsked whether Pitt would benefit from devising its own uniquely designed learning management system, or some sort of Pitt-only version of Oracle\u2019s PeopleSoft, to better fend off hackers who accessed many universities at once through the same software, Duska said: \u201cBuilding and running our own version of these systems, at the level of security that companies like Instructure and Oracle provide, would mean recreating years of specialized software development and dedicated security teams that these companies build up by serving thousands of institutions at once. That kind of scale isn\u2019t realistic for a single university to reproduce \u2014 and a homegrown system would carry its own risk of being hacked, without the added benefit of a vendor\u2019s dedicated security resources.\u201d<\/p>\n<p>\n\tHowever, he allowed, \u201cno institution can fully protect itself if the outside company providing its software is the one that gets breached. That\u2019s why resilience and fast response matters as much as prevention.\u201d<\/p>\n<p>\n\tThere\u2019s no specific reason to suggest that the particular student data accessed in the Canvas hack would be used to create stolen identities for anyone in the future, Duska said. \u201cInstructure has confirmed the information taken included names, email addresses, student ID numbers and messages exchanged between Canvas users. There\u2019s no evidence that passwords, dates of birth, Social Security numbers or financial information were involved.\u201d<\/p>\n<p>\n\tBut, of course, the hacker group that accessed Canvas and PeopleSoft, calling itself ShinyHunters, cannot be taken entirely on its word, he said, despite promises to destroy and not sell data: \u201cThere\u2019s never real certainty when dealing with criminal actors. Because of that, we treat any data that was taken as still being at risk \u2014 regardless of what the attackers claim.\u201d<\/p>\n<p>\n\tAsked what Pitt had learned from the Canvas and PeopleSoft incidents, Duska said: \u201cIn the Canvas incident, data was taken from Instructure\u2019s systems, not Pitt\u2019s own. In the PeopleSoft incident, Pitt\u2019s environment was scanned by our service provider and no evidence of compromise was found. Either way, a vendor\u2019s incident becomes an incident the University has to respond to \u2014 which is why institutions like Pitt continue to invest in vendor risk assessment, faster detection and monitoring, and clear, fast communication to the community.\u201d<\/p>\n<p>\n\tMarty Levine is a staff writer for the University Times. Reach him at <a href=\"https:\/\/www.utimes.pitt.edu\/news\/mailto:martyl@pitt.edu\" rel=\"nofollow noopener\" target=\"_blank\">martyl@pitt.edu<\/a> or 412-758-4859.<\/p>\n<p style=\"border-bottom:1px dashed #a8abbc;display:block;\">\n\t\u00a0<\/p>\n<p>\n\tHave a story idea or news to share? <a href=\"https:\/\/www.utimes.pitt.edu\/got-news\" rel=\"nofollow noopener\" target=\"_blank\">Share<\/a> it with the University Times.<\/p>\n<p>\n\tFollow the University Times on <a href=\"https:\/\/www.facebook.com\/PittTimes\" rel=\"nofollow noopener\" target=\"_blank\">Facebook.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"By MARTY LEVINE Pitt Digital has already taken a new step to prevent future Canvas hacks, such as&hellip;\n","protected":false},"author":2,"featured_media":258134,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[1594,10605,497,3398,73,75,74,1164,3315,10604,10603],"class_list":["post-258133","post","type-post","status-publish","format-standard","has-post-thumbnail","category-pittsburgh","tag-college","tag-graduate","tag-learning","tag-pitt","tag-pittsburgh","tag-pittsburgh-headlines","tag-pittsburgh-news","tag-research","tag-students","tag-undergraduate","tag-university"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/posts\/258133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/comments?post=258133"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/posts\/258133\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/media\/258134"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/media?parent=258133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/categories?post=258133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-pa\/wp-json\/wp\/v2\/tags?post=258133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}