Blog

Home » Blog » The Canvas Breach Isn’t Yours, but the Response Is
After the Canvas breach, schools don't need new tools. They need the right small actions.

The Canvas Breach Isn’t Yours, but the Response Is

By John Trest, CLO of Inspired eLearning

During one of the busiest periods of the school year, schools and universities in the US were targeted in an attack on the Canvas learning management platform. This disrupted online classes and raised concerns about data breaches involving student and faculty information.

While details about the event continue to unfold, many facts surrounding the Canvas breach are still unclear. The situation underscores a vital lesson: when educational institutions rely on a shared technological infrastructure like Canvas, a single vulnerability can rapidly transform into a widespread risk affecting hundreds or thousands of schools.

For education officials, instructors, administration staff, and parents alike, there is no need for undue alarm. Three simple, but key steps will help prevent further issues.

This Was a Supply Chain Breach: Audit Your Vendor Platforms

It’s important to consider where the Canvas breach began. Schools were not targeted individually; rather, the impact spread through a platform used by thousands of institutions.

More than ever, education relies on interconnected platforms to help students learn, communicate, assess performance, establish identity, and collaborate. Each of these platforms stores information outside of the school’s walls.

In many instances, that data includes:

  • Past class records
  • Stored assignments
  • Previous student communications
  • Previous uploads
  • Former employee accounts
  • Duplicate data sets stored for easy access

If a vendor is compromised, all of that information can become part of the exposure footprint.

This means schools should expect education technology providers to face more scrutiny, and unfortunately, more incidents involving third-party platforms. The education sector is an attractive target for bad actors thanks to the high volume of personal data involved, large, open networks, and the operational pressure schools face to be accessible and responsive.

The good news is that one of the most effective controls is also one of the simplest: reduce unnecessary data exposure.

It’s now a good time to:

  • Consider which platforms are strictly necessary
  • Delete any out-of-date entries and legacy content as allowed by policy
  • Archive or securely destroy historical content that includes student information
  • Review your vendors’ retention policies
  • Ask them what data they hold, for how long, and who can access it

Data that is not stored within a vendor’s system cannot be stolen from it.  This is one of the few security controls that pays off even if a vendor is compromised.

Send One Pre-Emptive Message

Based on reports of the incident, there is evidence that the stolen data may include information on institutions, courses offered, instructor names, student identities, and contact numbers, which could be useful to impersonators.

Schools and universities can expect a slew of phishing campaigns soon, with emails that seem genuine because the details they contain are all too recognizable. They might use real class names, real instructors, or familiar administrative language.

Potential examples include:

  • ‘New assignment for [real class name]’
  • ‘Action required from [real teacher]’
  • ‘Your student account has been compromised. Confirm your password’

The best way to counter phishing is with a brief but polite explanation to parents, students, teachers, and other school personnel. That can effectively limit the impact of such threats.

This communication must include information on what the school will never ask for via email, the kinds of emails the school sends, which websites are legitimate for sending information, what to do if there is suspicion of fraud, and whom to contact.

The message should not speculate what data may or may not have been exposed. Its purpose is to set expectations before impersonation attempts start to appear in inboxes.

This pre-emptive message is a small operational step with a big impact. Phishing campaigns work because recipients are surprised, rushed, or uncertain.

This takes away any ambiguity and demonstrates leadership. During these times when schools might not have all the answers, it is critical for them to demonstrate awareness, communication, and assistance in responding appropriately.

Update the Conversation, Not Just the Curriculum

One lesson schools and universities can learn from incidents like the Canvas breach is that the greatest risk to student data doesn’t always come from obvious online dangers, but from the ordinary, trusted systems they use every day.

It will change the way that these discussions take place. Cyberbullying, stranger danger, downloading risks, and keeping passwords safe have hogged the spotlight for many years now. These are still critical, but students need to learn what happens to their personal data, how it’s kept secure, and why sharing less is important, too.

The next major education-sector incident will probably look similar to this one: a trusted platform, a treasure trove of data, and thousands of institutions affected at once.

The good news is that schools don’t need to redesign their curricula to respond effectively. In fact, sometimes 10 to 15 minutes a week is enough to build awareness. These discussions should cover topics such as:

  • The nature of student data
  • Why platforms collect and keep student data
  • Where third-party providers fit within the school system
  • The importance of minimum disclosure
  • How to pinpoint impersonation attempts

These conversations are most effective if the language is consistent among students, parents, and teachers.

Add Structured Awareness

This is also where structured awareness tools can prove helpful in reinforcing such conversations at an age-appropriate level. Tools such as VIPRE Security Training for Students provide schools with useful support in forming these habits without additional operational strain.

The Canvas breach is a good example of how cybersecurity in educational institutions goes beyond technology. The response should be about safeguarding trust, continuity, and overall student safety.

Previous Post
Digital Natives are Digital Naïves: Child Online Safety is More Than Screen Time Rules

Related Posts

keyboard_arrow_up
AdChoices Do Not Sell My Personal Information