Instructure is an ed-tech giant best known for Canvas, a "learning management" system used by schools at all levels to help manage coursework, assignments, and online learning. Attackers claim to have taken over 240 million records tied to students, teachers, and staff containing names, email addresses, enrolled courses, and private messages. If true, evidence suggests the dataset spans 15,000 institutions in North America, Europe, and Asia. At this time little else has been said, but attackers have also been causing downtime on the platform itself, disrupting students as finals are right around the corner.
Shinyhunters don’t have Canvas listed on their website right now, so maybe a deal is being made… (complete speculation you should ignore)
A small update to a story from last week. While Vimeo still hasn’t officially confirmed how many victims this attack impacted, Have I Been Pwned says it uploaded the email addresses of 119,200 people. Since HIBP analyzes data before sharing, this means it’s possible that there were more victims than that but only that many were new email addresses.
Doesn’t HIBP add the email addresses for each leak? It’s not like your email has been leaked on one service and then they won’t add it again assigned to a different leak. Idk, i’m just not totally sure what that bit means.
Going on shinyhunters website is enlightening and I think can help convince yourself or others that any data that you give away is a huge liability.
I was under the impression they try not to add duplicate data. I’ve seen other articles where HIBP specifies how many new email addresses are added vs how many ones were already in their database.