Aus universities and TAFEs investigating exposure to Canvas cyber incident

By
Follow google news

Learning management system vendor targeted.

Australian universities and TAFEs have joined global counterparts in scrambling to understand their potential exposure to a cyber incident involving a popular learning management system.

Aus universities and TAFEs investigating exposure to Canvas cyber incident

Multiple institutions including RMIT University, UTS, TasTAFE Tasmania and Western Sydney University revealed their potential exposure in disclosures over the past 24 hours.

Of these, TasTAFE provided the most detailed view of the incident, which it said impacted “data associated with some [Canvas] customer accounts”, including its own.

TasTAFE said that Canvas’ owner Instructure first notified of the cyber incident on May 2, but had yesterday provided further details, advising “that a criminal third party” was involved.

“This incident relates to Instructure’s systems and was not the result of a breach of TasTAFE’s own systems or processes,” TasTAFE wrote.

“Investigations commenced immediately and are ongoing. Based on current advice, the data involved may include some personal information, including content stored within Canvas such as messages.

“At this stage, Instructure has not provided TasTAFE with information identifying specific individuals affected.

“There is no indication that passwords, dates of birth, government identifiers, or financial information were involved.”

RMIT University wrote in a brief notice that it is “working with the vendor to confirm if RMIT data has been involved and understand any impacts as a result of this breach.”

A similarly-worded UTS missive stated that it is “working with the vendor, Instructure, to confirm whether UTS data has been compromised as part of this incident and to fully understand potential impacts if a breach has occurred. 

“We are also working with relevant Australian authorities,” UTS wrote.

Western Sydney University similarly said it was working with the vendor to examine potential exposure.

All institutions said that Canvas was operating normally within their environments.

A well-known threat group has claimed responsibility for the attack.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

Defender yanks root certs as Windows updates blocks backups

Defender yanks root certs as Windows updates blocks backups

Log In

  |  Forgot your password?