
More than 153,886 students and staff from four educational institutions in Hong Kong were affected by a data breach on the online learning platform Canvas, according to an investigation by the Office of the Privacy Commissioner for Personal Data (PCPD).
While City University of Hong Kong (CityU) reported that data of 146,969 of its students and staff were exposed, the Hong Kong Academy for Performing Arts (HKAPA) and the Hong Kong Institute of Construction (HKIC) reported 4,584 and 2,333, respectively.
Data from the Hong Kong University of Science and Technology (HKUST) is pending verification by Instructure Holdings, Inc, which operates the web-based learning management platform.
The leaked information mainly included names of students and staff, email addresses, usernames, student IDs, course enrolment information, login IDs and messages sent by the users, the office said as it announced its findings on Thursday.
The incident did not affect the internal systems of the affected institutions, it added.
Instructure discovered that hacking group ShinyHunters carried out unauthorized activities in Canvas through a “Free-For-Teacher” account to exfiltrate user data on April 29.
RELATED ARTICLES
“Upon detecting the unauthorized activities, Instructure immediately blocked the unauthorized access and engaged a cybersecurity firm, CrowdStrike (a network security company), to initiate an independent investigation,” the PCPD said in a statement.
But on May 7, ShinyHunters exploited another security vulnerability to re-access Canvas and defaced the login pages of some educational institutions to post a ransom note, it added.
The PCPD launched its investigation following data breach notifications by seven educational institutions between May 6 and 11. The institutions are: CityU, the HKAPA, the HKIC, the HKUST, Hong Kong Art School, Polytechnic University and Hong Kong Education City.
Upon investigation, the PCPD found only four — CityU, HKAPA, HKIC and HKUST – were actually affected.
“According to Instructure, the threat actor submitted a support request containing malicious code through the account and exploited a cross-site scripting vulnerability in the platform to obtain an authorization token and gain elevated access within Canvas to carry out unauthorized activities and exfiltrate personal data,” reads the PCPD statement.
Instructure later fixed the security vulnerabilities, strengthened security measures and discontinued the “Free-For-Teacher” service before resuming Canvas services on May 9. Two days later, Instructure announced reaching an agreement with the attacker and retrieved the stolen data.
The PCPD investigations found that the affected institutions had conducted pre-assessments before deploying Canvas, adopted contractual means and established monitoring mechanisms to safeguard the personal data transferred to Canvas.
There is no evidence to suggest that the four educational institutions had failed to take all practicable steps to safeguard the personal data in their possession while using Canvas, and therefore there was no contravention of the PDPO, said Privacy Commissioner for Personal Data Ada Chung Lai-ling.
To ensure data security, the PCPD recommended that the educational institutions concerned should reassess the risks of data breaches, boost monitoring of security measures implemented by third-party platforms, minimize the amount of personal data stored on such platforms and enable multi-factor authentication.
