Stolen Canvas data was “returned” after hacker agreement, Instructure says
ID: 0f8d62d0-1822-55c1-bf80-e269f4eaaf72
STIX ID: report--0f8d62d0-1822-55c1-bf80-e269f4eaaf72
Feed Name: Malwarebytes Blog
The article covers a data breach of Instructure/Canvas claimed by the extortion group ShinyHunters, noting Instructure reportedly paid the actor and that the stolen data was "returned" and logs "shredded." Exposed items include usernames, emails, course names, enrollment details, and private messages — data sufficient to enable targeted phishing and social engineering; the vendor states no passwords, DOBs, government IDs, or financial data were involved. Recommended actions for affected users include resetting Canvas passwords, enabling MFA, monitoring financial/credit activity, and remaining vigilant for personalized phishing attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
