ITS Calls for Vigilance After Canvas Service Disruption

0
28

Key Takeaways

  • The cyberattack on Instructure’s Canvas platform caused a temporary outage for thousands of institutions last Thursday, but service has been fully restored.
  • Metropolitan State University of Denver’s Information Technology Services (ITS) review indicates that only limited user data—such as names, email addresses, student ID numbers, and course‑related information—may have been exposed.
  • No evidence suggests that highly sensitive personal or financial data (passwords, Social Security numbers, banking details, etc.) were compromised.
  • A concurrent phishing campaign has been observed; ITS urges all campus members to remain vigilant when handling unsolicited emails, links, or requests for information.
  • As a precaution, faculty should download gradebooks and class rosters from Canvas and ensure lecture materials, assignments, and other resources are backed up.
  • Users are encouraged to monitor the Information Security Updates page for ongoing developments and to report any suspicious activity to ITS via phone (303‑352‑7548) or the service portal.
  • Following basic phishing‑prevention practices—such as verifying sender addresses, avoiding unexpected attachments, and using multi‑factor authentication—can significantly reduce risk.

Incident Overview and Immediate Impact

Last Thursday, a cybersecurity incident targeting Instructure, the vendor behind the widely used Canvas learning management system, forced the platform offline at thousands of educational institutions across the United States. The disruption lasted several hours, affecting class schedules, assignment submissions, and access to course materials. Instructure’s engineering teams worked rapidly to isolate the threat, apply patches, and restore service. By the end of the day, Canvas was reported as fully operational nationwide, allowing universities to resume normal academic activities. The swift response limited the duration of the outage, but the event highlighted the dependence of modern education on cloud‑based services and the potential ripple effects when those services are compromised.

MSU Denver’s Assessment of Data Exposure

Metropolitan State University of Denver’s Information Technology Services (ITS) conducted a thorough review of the breach’s implications for its community. According to ITS, the exposed information may have included users’ names, email addresses, student identification numbers, and certain course‑related details such as enrollment status or assignment titles. Importantly, the review found no indication that passwords, Social Security numbers, banking information, or other categories of highly sensitive personal or financial data were accessed or exfiltrated. This distinction is crucial because it reduces the risk of identity theft or financial fraud, though it does not eliminate concerns about privacy or potential misuse of the less‑sensitive data that was exposed.

Ongoing Monitoring and Threat Landscape

In the aftermath of the Canvas incident, MSU Denver’s ITS has heightened its monitoring efforts to detect any further suspicious activity that could signal a continuation or escalation of the attack. Analysts are reviewing logs for anomalous login attempts, unusual data transfers, and signs of lateral movement within the university’s network. The team has also noted a recent phishing campaign that appears to be leveraging the publicity surrounding the breach. These fraudulent emails often masquerade as official communications from Instructure, ITS, or university leadership, attempting to trick recipients into divulging credentials or downloading malicious payloads. By maintaining active surveillance, ITS aims to identify and neutralize threats before they can cause harm.

Phishing Vigilance and Best Practices

Given the observed phishing surge, ITS urges all students, faculty, and staff to exercise heightened caution when interacting with electronic communications. Key defensive measures include: verifying the sender’s email address for subtle misspellings or domain inconsistencies; hovering over links to preview the actual URL before clicking; refraining from opening attachments from unknown or unexpected sources; and never providing passwords, Social Security numbers, or financial details in response to an unsolicited request. Additionally, enabling multi‑factor authentication (MFA) on university accounts adds a critical layer of protection, ensuring that even if credentials are compromised, unauthorized access remains difficult. Regularly updating passwords and using unique, complex passphrases further reduces risk.

Precautionary Actions for Faculty

As a proactive safeguard, faculty members are advised to download their Canvas gradebooks and class rosters to secure, locally stored devices or approved university storage solutions. This practice ensures that essential grading information remains accessible even if the Canvas platform experiences future interruptions. Moreover, ITS recommends backing up lecture recordings, slide decks, assignment prompts, and any other instructional materials to multiple locations—such as encrypted external drives, university‑approved cloud storage, or version‑controlled repositories. Maintaining recent backups not only mitigates data loss from cyber incidents but also protects against accidental deletion, hardware failure, or ransomware attacks.

Utilizing Official Communication Channels

To stay informed about the evolving situation, the university community should routinely consult the Information Security Updates page hosted on the MSU Denver website. This centralized repository provides official statements, timelines, mitigation steps, and FAQs related to the Canvas breach and any related security events. By relying on vetted sources, individuals can avoid misinformation that often circulates during cybersecurity incidents and receive accurate guidance on protective actions. ITS also encourages users to subscribe to email alerts or RSS feeds from this page to receive real‑time notifications.

Reporting Suspicious Activity

If any member of the university observes unusual behavior—such as unexpected login prompts, unexplained changes to account settings, or receipt of suspicious emails—they should report it promptly to the Information Technology Services help desk. Reports can be submitted via phone at 303‑352‑7548 or through the ITS service portal, where tickets are triaged and investigated by security analysts. Timely reporting enables ITS to correlate events across the campus, potentially uncovering broader attack patterns and facilitating a rapid, coordinated response.

Summary of Recommendations and Forward‑Looking Perspective

The Canvas cyberattack serves as a reminder of the interconnected nature of modern educational technology and the importance of layered security defenses. While the breach exposed only limited, non‑critical data at MSU Denver, the associated phishing attempts underscore that attackers often exploit publicized incidents to launch secondary campaigns. By adhering to the outlined best practices—vigilant email handling, MFA enrollment, regular data backups, and prompt reporting—students, faculty, and staff can significantly reduce their vulnerability. Continued collaboration between ITS, university leadership, and service providers like Instructure will be essential to hardening defenses, improving incident response times, and preserving the trust and reliability of digital learning environments.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here