A notorious hacking group has carried out a significant breach of the Canvas academic software, impacting thousands of schools and universities across the United States. The breach, which was carried out by the hacking group known as 'Individual', has compromised sensitive data belonging to students, staff, and faculty at affected institutions.
According to reports, the hacking group accessed the Canvas system by exploiting a vulnerability in the software's coding. This allowed them to gain entry to the system and extract sensitive information, including personal details and educational records.
The US Department of Education has issued a statement condemning the breach and reassuring students that their data is being protected. The department has also urged affected institutions to take immediate action to secure their systems and protect student data.
While the breach has raised concerns over education system security, it is worth noting that Canvas is widely used in the UK, with many universities and schools employing the software. However, at the time of writing, no immediate disruption to UK institutions has been reported.
The UK's National Cyber Security Centre (NCSC) has issued guidance to UK universities and schools using Canvas, advising them to remain vigilant and take steps to protect themselves against similar breaches. The NCSC has also encouraged affected institutions to report any incidents to the relevant authorities.
In a statement, a spokesperson for the US Department of Education said, 'We take the security of student data very seriously and will continue to work with affected institutions to ensure that their systems are secure and that student data is protected.'