Major cybersecurity breach affects student data in NYC public schools and Columbia University.
New York City has been embroiled in what is being labeled the most significant student data privacy breach in history, impacting both universities and K-12 educational institutions. This assertion was made by school officials on Friday, who confirmed the widespread ramifications of a cyberattack that targeted Canvas, a widely utilized online education platform that facilitates course materials and communication between educators and students.
On Thursday, Canvas experienced extended downtime, coinciding with a critical period during which many college students were preparing for final examinations. Hackers identifying themselves as “ShinyHunters” claimed responsibility for the breach, which they alleged impacted approximately 9,000 educational institutions, compromising billions of private messages and records. This group is notorious for previous cyber offenses, including a major breach involving Ticketmaster.
By Friday, access to Canvas had largely been restored, as reported by officials from the education technology company Instructure, the provider of the platform. New York City Schools Chancellor Kamar Samuels addressed the situation in a statement, acknowledging two recent data privacy issues, one of which involved Canvas and affected seven public schools.
Samuels emphasized the city’s commitment to safeguarding student data and the prioritization of technology usage in schools. He underlined the rapid response of the administration upon learning of the breach, highlighting ongoing collaboration with relevant law enforcement agencies and the NYC Cyber Command to address and resolve the crisis effectively.
The outage also disrupted operations at Columbia University during its reading week, a critical time between the conclusion of classes and the onset of final exams. Consequently, all exams and assignments due that Friday were postponed at Columbia’s Mailman School of Public Health, which also utilizes the Canvas platform, alongside the affiliated Barnard College.
In contrast, representatives from New York University and the City University of New York (CUNY) clarified that they do not employ Canvas, opting for alternative vendors that provide similar services. Instructure’s spokesperson indicated that the company had identified the hacker’s exploitation of free teacher accounts, which have since been temporarily suspended to prevent further unauthorized access.
The breadth of this incident raises significant concerns regarding data privacy in educational settings and the safeguarding of sensitive information. The second data privacy issue alluded to by Chancellor Samuels does not involve Canvas and further underscores the ongoing scrutiny and challenges facing New York City’s educational institutions in protecting student data.
A recent audit conducted by State Comptroller Tom DiNapoli found substantial weaknesses in the city’s student data privacy policies, reinforcing the urgent need for enhanced security measures across all educational programs.
As educational institutions continue to navigate these complex challenges, officials are committed to transparency and communication with affected students, faculty, and families, ensuring that appropriate measures are implemented to restore confidence in the protection of sensitive information.
Media News Source
