More than 153,000 students, staff affected in Canvas data breach: privacy watchdog
More than 153,000 students and staff from four tertiary institutions in Hong Kong have been affected by a data breach on the online learning management platform Canvas, an investigation by the city’s privacy watchdog has found. Nearly four months after the data breach was discovered, the Office of the Privacy Commissioner for Personal Data (PCPD) said on Thursday that the incident stemmed from…
A data breach on the learning management platform Canvas has affected over 153,000 students and staff across four tertiary institutions in Hong Kong, according to a privacy watchdog investigation. The Office of the Privacy Commissioner for Personal Data (PCPD) discovered the issue nearly four months after its discovery, tracing it back to "vulnerabilities relating to a third-party platform."
Nearly all affected individuals, 96%, originated from City University of Hong Kong (CityU), with 96% of CityU's 153,866 affected accounts being active user accounts.
The leaked data included basic identifiers such as names, student IDs, and email addresses, but did not involve any sensitive personal information. The Hong Kong Academy for Performing Arts, Hong Kong Institute of Construction, and Hong Kong University of Science and Technology also experienced breaches, with 4,584, 2,333, and an unspecified number of affected individuals, respectively.
The PCPD noted that the institutions had taken appropriate precautions before using Canvas and had established monitoring mechanisms to protect the personal data transferred to the platform.
Instructure, the company behind Canvas, revealed that hackers had stolen personal data from around 9,000 institutions worldwide, including seven in Hong Kong, impacting a total of 72,571 people. The company resolved the breach by agreeing to return the stolen data in May. The PCPD advised the affected institutions to reassess their risks of data breaches, enhance monitoring of third-party platform security measures, limit personal data storage, enable multi-factor authentication, and define clear access rights and data retention periods.
Written by urgent.news from South China Morning Post - Hong Kong's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.