This is a developing story and will be updated as more information becomes available. Last updated May 9 at 8 p.m.
Northwestern’s Canvas site is back up as of Saturday morning after being down since Thursday afternoon following an alleged cybercrime breach.
The cybercrime group ShinyHunters claimed Thursday to have breached Instructure, the owner of learning site Canvas, for a second time. NU’s Canvas site directed to a message from ShinyHunters message earlier Thursday afternoon, before switching later that day to a scheduled maintenance message on the initial login page.
“Core Canvas access is restored, and the service is now available to the campus community. Many Canvas integrations are enabled and ready to access, including Zoom, Panopto, Microsoft, Google, Turnitin, and more,” a Canvas announcement read Saturday morning. “Others may not yet be available and will be enabled on a rolling basis.”
In a Saturday morning email that reiterated the updates from the Canvas announcement, Sean Reynolds, NU’s vice president for information technology and chief information officer, also wrote the University community should remain alert for “Canvas-themed phishing attempts.”
He also wrote that instructors should download their course site gradebooks as a precaution.
The University’s Canvas site went down at around 3 p.m. Thursday. It appeared to be back up around 9 p.m. Thursday and again around midnight Friday before returning to the maintenance message.
A Friday update to the University IT Services incident report at 9:13 a.m. stated that Canvas was still unavailable for use.
“Conversations with other institutions, security experts, and the vendor are continuing regarding next steps for reconnecting Canvas,” according to the report.
In an incident report Thursday at 3:41 p.m., Instructure wrote that Canvas, Canvas Beta and Canvas Test were unavailable. The company wrote in an update Thursday night that Canvas was available for most users.
In an email to the University community on Thursday at 4:51 p.m., Reynolds wrote that NUIT was monitoring the situation. He also confirmed that other institutions were experiencing the same issue with their Canvas sites.
“While we don’t have an estimated restoration time from the vendor, please know this incident is not impacting other information technology infrastructure at Northwestern,” Reynolds wrote.
The breach impacted students’ learning starting Thursday. Weinberg senior Charlotte Kohner said they were taking a remote biology exam — their first “real exam” of Spring Quarter — when Canvas went down.
“I’m just hoping my grade is good enough as is and wasn’t affected by the hack,” Kohner said.
SESP junior Ty Moyer said he hopes faculty understand that without Canvas, students may not be able to complete their work on time.
Moyer added that he believes students should not be penalized for Canvas’ issues. Professors should allow students to make up exams or push back submission dates, he said.
“Because this is the middle of the quarter, we have flexibility to change the schedule,” he said. “They should offer that to students and work with faculty to create new syllabus timelines.”
ShinyHunters claims that more than 9,000 schools worldwide have been affected by the latest breach. In the last week, ShinyHunters has breached the Canvas sites of other institutions nationwide, including the University of Pennsylvania, Princeton University and Duke University, according to their student publications.
“If any of the schools in the affected list are interested in preventing the release of their data, please consult with a cyber advisory firm and contact us privately at TOX to negotiate a settlement,” the ShinyHunters message posted on NU’s Canvas read. “You have until the end of the day by May 12 before everything is leaked.”
On May 1, Instructure wrote in an incident report that it was experiencing a “cybersecurity incident perpetrated by a criminal threat actor.” The company wrote it was working with external forensics experts to minimize the impact of the incident.
In a May 2 update to the report, the company’s chief information security officer, Steve Proud, wrote the investigation was ongoing, but the company believed the incident had been contained.
“While we continue actively investigating, thus far, indications are that the information involved consists of certain identifying information of users at affected institutions, such as names, email addresses, and student ID numbers, as well as messages among users,” Proud wrote. “At this time, we have found no evidence that passwords, dates of birth, government identifiers, or financial information were involved.”
Instructure wrote Wednesday that Canvas was “fully operational” following the first breach.
Liam Barrett contributed reporting.
Email: [email protected]
Email: [email protected]
X: @anavi_52
