Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

150k people affected by Canvas data breach

More than 150,000 students and staff of four educational institutions were affected by a data breach on the online learning platform Canvas, an investigation by the Office of the Privacy Commissioner for Personal Data has found. The breach, discovered by platform operator Instructure on April 29, involved a hacking group using a "Free-For-Teacher" account to exploit a cross-site scripting…

The online learning platform Canvas experienced a data breach that impacted over 150,000 students and staff members from four educational institutions in Hong Kong. The breach was discovered by its operator, Instructure, on April 29 and was traced back to a hacking group that exploited a cross-site scripting vulnerability through a free-for-teacher account.

Personal information such as names, email addresses, usernames, and student IDs were stolen during the cyberattack. At first, seven institutions reported potential breaches, but further investigation revealed that only four – City University, Hong Kong Academy for Performing Arts, Hong Kong Institute of Construction, and Hong Kong University of Science and Technology – were actually affected.

City University disclosed that 146,969 students and staff had their data exposed, while HKAPA and HKIC had about 4,584 and 2,333 records compromised, respectively. The status of HKUST's data is still under verification. Ada Chung, the Privacy Commissioner for Personal Data, stated that the affected institutions had taken necessary precautionary measures before using Canvas, including pre-assessments, contractual safeguards, and monitoring mechanisms.

She concluded that the institutions had not violated the Personal Data (Privacy) Ordinance as there was no evidence of failing to take all practicable steps to protect the personal data in their possession. Chung emphasized the importance of thorough due diligence on data processors, regulating them through contracts, and enabling security features like multi-factor authentication.

Written by urgent.news from RTHK News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at news.rthk.hk →

More in Tech

"Agent 协议栈三层分化:MCP 管工具、A2A 管协作、Agent Plugins 管分发"

Agent 协议栈三层分化:MCP 管工具、A2A 管协作、Agent Plugins 管分发 2026年8月,协议战结束了。 这不是说竞争消失了——而是战场发生了转移。半年前,开发者还在热烈争论"MCP vs 其它协议哪个更好",而现在答案已经清晰得让人有点意外: 没有哪个更好,只有哪个更适合哪一层。 三层架构是如何成形的 先说背景。AI Agent…

More from Thursday 20 August →