Around the morning of May 8, HAU students reported errors in log-in attempts into the Canvas learning management system (LMS), its page displaying the message, “Canvas is currently undergoing maintenance”. This maintenance coincided with Instructure, the company behind Canvas, investigating a cybersecurity breach. The prolific data extortion group “ShinyHunters” took responsibility and threatened to leak allegedly stolen data unless their ransom is met. Canvas LMS is used by at least 8,000 institutions worldwide. As of 11 AM, Canvas became available again for HAU students; available again “for most users,” said Instructure.
In an interview, Mr. Kevin Espinosa, head of the Learning Management System Office of Holy Angel University, stated he had been in communication with the university’s deans and chairs that Instructure is investigating the matter of the maintenance and the data breach, and that he is in open communication with Instructure’s customer access manager. He has been in close contact about the situation with the maintenance, and communicating since May 7 to address the alleged data breach.
Instructure assured Mr. Espinosa that student and educator data is safe, stating, “everything is in place,” and stated in an email that they were working to determine which institutions were affected.

Schools in the United States reported seeing a message when attempting to open the Canvas LMS website, where the threat actor detailed their attack and extortion, including a now-inaccessible text file that lists the schools allegedly affected by the data breach. The text file listed Holy Angel University, as well as many other schools locally and worldwide, including Angeles University Foundation, De La Salle University, Columbia University, Harvard, and the University of California.
However, Mr. Espinosa notes that the list does not verify that Holy Angel University was actually affected. “The good thing now is that we are just subscribed to the LMS,” saying that HAU’s systems were “created manually,” and are “not API-based.” He noted, “Based on my reading, what were affected were mostly integrated accounts,” referring to accounts integrated into multiple Instructure services.

This is not the first attack that the group has made against Instructure’s Canvas learning management system (LMS). Since May 1, the hacker group has attacked and publicly threatened Instructure through alleged data breaches involving identifying information, before escalating to the current extortion campaign.
The allegedly exposed identifying information includes names, emails, student ID numbers, and user messages. They claim to have exfiltrated 3.65TB of information. However, Instructure reportedly stated that passwords, financial information, and government IDs were not believed to have been exposed.
Dark Reading’s Alexander Culafi wrote in an article, “One concern would be whether attackers could use information gained from these messages as an additional extortion lever against institutions or families. Specific identifying information like this would also be useful for follow-on phishing activity.” Although, as Mr. Espinosa noted, it is not verified whether Holy Angel University was actually affected by the data breach.
ShinyHunters uses its dark web leak site to publish allegedly exfiltrated data when ransom demands are unmet. At the time of writing, references to Instructure and Canvas were no longer publicly visible on the site, though the reason for their removal remains unclear.
By Pocholo Tolentino




Leave a Reply