The hacker responsible for a breach at education technology company Instructure claims to have stolen 2CO million records tied to students and staff from 8,809 colleges, school districts, and online education platforms.
The ShinyHunters extortion gang has claimed responsibility for the attack. The threat actors published a list of impacted institutions, sharing record counts per institution that range from tens of thousands to several million per institution.
Instructure, which provides the cloud-based Canvas learning management system used for managing coursework and communication, disclosed it was investigating a cyberattack last Friday. The company later revealed that the breach exposed users' names, email addresses, and private messages.
The threat actor claims the data theft was achieved using Canvas data export features, including user APIs, provisioning reports, and DAP queries. According to the hacker, hundreds of gigabytes of enrollment data, messages, and user records were harvested.
Various universities have issued statements regarding the incident. The University of Colorado Boulder stated it is aware of a nationwide data breach involving Instructure and noted that it is a reported event affecting multiple institutions.
Rutgers indicated that while they have not been notified of any direct impact to their campus, Canvas remains operational for faculty, staff, and students. Tilburg University stated an investigation is underway to determine if student or staff data was impacted and noted that further questions have been submitted to the supplier.