AUTO-UPDATED

Canvas Pauses Data Delivery Due to Potential 'Security Threat'

Instructure has paused the distribution of data related to a recent Canvas learning management system breach after identifying a potential security vulnerability within its chosen third-party delivery platform.

Key Points

  • The educational software company Instructure delayed sharing breach-related data with 9,000 institutions following a security concern involving its third-party delivery provider.
  • In May, the hacking group ShinyHunters claimed to have accessed personal information for 275 million users, including names, email addresses, and student ID numbers.
  • Instructure CEO Steve Daly stated that the company’s internal data remains secure and that the pause is a precautionary measure to ensure safe information transfer.
  • Canvas is currently utilized by 41 percent of higher education institutions across North America for course delivery and management.

Why it Matters

This delay highlights the ongoing security challenges institutions face when managing sensitive student data across multiple digital platforms and third-party vendors. The incident underscores the critical importance of vetting supply chain security to prevent secondary vulnerabilities during the remediation of major cyberattacks.
Inside Higher Ed Published by kathryn.palmer@insidehighered.com
Read original