
School Portal System Canvas Hit by Security Flaw Allowing Hackers to Post Messages
Instructure confirmed that hackers exploited a weakness in Canvas, the online learning system used by many schools, to modify login pages and post extortion demands.
Source
BleepingComputer
Original headline: Instructure confirms hackers used Canvas flaw to deface portals
Plain-English summary by GetCyberRight. Read the full report at the source above.
Education technology company Instructure has confirmed that hackers found and used a security vulnerability in Canvas, their widely used online learning platform. The security flaw allowed attackers to change what appeared on Canvas login portals and leave extortion messages. Canvas is used by many schools, colleges, and universities for online learning, assignment submission, and communication between teachers and students. If your children's school or your own educational institution uses Canvas, you may have been affected by this incident. The hackers were able to modify the login pages that students and parents see when accessing Canvas. While Instructure has confirmed the vulnerability exists, the company has not provided details about how many schools were affected or what specific information, if any, was compromised beyond the defaced login portals.
Take these steps right now if your school uses Canvas:
- Change your Canvas password immediately by going directly to your school's official Canvas website (type the address yourself, do not click links in emails).
- If you use the same password for Canvas that you use anywhere else, change those other passwords too.
- Enable two-factor authentication on your Canvas account if your school offers this option.
- Contact your school's IT department or administration to ask what specific information may have been compromised and what steps they are taking.
- Watch for suspicious emails that claim to be from Canvas or your school, especially any requesting personal information or payment. Online learning platforms hold significant information about your family, including student records, grades, and contact details. Always use unique passwords for educational platforms, and never reuse passwords across multiple sites. Teach your children to recognize suspicious activity on their school accounts and to report it to a teacher or parent immediately. When schools send notifications about security issues, read them carefully and follow their recommended steps.
Curated from trusted cybersecurity sources by GetCyberRight
Source: BleepingComputerStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Canvas Paid Hackers After Student Data Was Stolen During Finals Week
The learning platform used by millions of students just paid ransom to hackers. Here's what families need to know and do right now.
3 min readApple Patches Flaw That Could Expose Your Deleted Messages
Apple fixed critical security holes, including one that could recover deleted chats. Here's what families need to know and do right now.
3 min readApple Just Fixed Critical Security Holes: Update Your Devices Today
Apple released urgent patches for dozens of vulnerabilities in iPhones, iPads, and Macs. One fix stops deleted messages from being recovered without your knowledge.
3 min read
School Portal System Canvas Hit by Hackers Leaving Extortion Messages
Hackers changed login screens for Canvas, used by many schools. If your child's school uses Canvas, watch for suspicious messages and contact the school.
2 min read