THE WIRE · UPDATED 4:14 PM MDT No story is too small.
NewsSt. George

Utah schools warn of scams after Canvas cyberattack causes data breach

AI-written from public sources Written by Utah News AI and quality-checked before publishing.
A glowing laptop sits on an empty school desk in a dark room, partially covered by a large metal padlock, symbolizing a data breach and cyberattack on educational systems.
Photo via AI illustration
Utah school districts and universities have issued warnings regarding potential phishing scams following a cyberattack on Canvas that caused a major data breach. The incident involving the learning management system potentially exposed personal information for millions of users nationwide.

Key takeaways

  • A cyberattack on the Canvas learning management system has potentially exposed personal information for millions of users.
  • Multiple Utah school districts, including Box Elder, Logan City, and Murray City, have been impacted or notified of the breach.
  • Officials warn of an increase in phishing scams and advise against clicking suspicious links or providing credentials via email.
  • Many districts reported that sensitive data such as passwords, social security numbers, and financial information do not appear to be compromised.

Utah school districts and universities have released statements warning parents of possible phishing scams following a cyberattack on Canvas that caused a major data breach. The cyberattack on the popular learning management system potentially exposed the personal information of millions of users, according to reports.

While it remains unclear which specific districts and schools were compromised, many institutions are working to identify potential issues and inform both parents and the Utah State Board of Education.

The breach involved Instructure, the company behind Canvas. Various Utah districts have reported different levels of impact. Box Elder School District confirmed that names, institutional email addresses, student ID numbers, and Canvas messages may have been affected, though they noted no evidence that passwords or financial information were compromised.

Logan City School District and Murray City School District also reported being impacted by the incident. Murray City School District noted that the breach did not result from a security failure within their own systems but was part of a nationwide incident affecting approximately 275 million users. The district has since reauthorized secure API keys as a precaution.

Other districts, such as Daggett, Granite, and North Sanpete, reported being notified of the incident. While some indicated that certain types of sensitive data like passwords or social security numbers were not involved, they warned of an increase in phishing attempts.

Utah State University temporarily suspended Canvas after unauthorized changes were made to some pages across various universities. Officials at USU worked to minimize impacts on students and faculty, noting that Instructure later restored service. At the time of the report, there was no indication that USU systems themselves were compromised.

In Ogden School District, officials decided to keep the connection between Canvas and the Infinite Campus student information database offline through the weekend as a precaution. This measure prevents grades and assignments from being imported until further guidance is provided.

Educational officials are advising parents and students to be extra cautious with emails that ask for information or create a sense of urgency. Recommended precautions include not clicking external links in Canvas, manually typing official URLs into browsers, and being wary of unexpected attachments.

Districts such as Kane County School District emphasized that they do not store student Social Security numbers, reducing the risk of identity theft related to this specific breach.

Article details

CategoryNews
CitySt. George
ToneNeutral
SourceAI Generated