Hackers deface school login pages after claiming another Instructure hack | TechCrunch
Briefly

Hackers deface school login pages after claiming another Instructure hack | TechCrunch
"Hackers were able to compromise Instructure again - this time defacing several schools' login pages to the company's platform Canvas, which allows schools to manage coursework and assignments and communicate with students. TechCrunch saw a message published by the cybercrime group ShinyHunters on the Canvas login pages of three separate schools. A review of the defaced portals shows that the hackers injected an HTML file that altered the login screens to display their message."
"The message says the hackers will publish the stolen data on May 12 if the company does not "negotiate a settlement." At the time of writing, Instructure's website appeared to be partially online, at times returning a "too many requests" error. The company's Canvas portal displayed a notice saying it was "currently undergoing scheduled maintenance." Instructure did not immediately respond to TechCrunch's request for comment."
"ShinyHunters had previously claimed responsibility for the original hack, publicizing it on its leak site - a website hackers use to publish stolen data and pressure victims into paying ransoms - in an effort to extort Instructure into paying to keep the data from going public. This apparent new hack, along with the fact that hackers chose to notify TechCrunch about the defaced login pages, indicate that the hackers are trying to ramp up pressure on Instructure and its customers, hoping to force them to cave to the hackers' demands."
"It's unclear how the hackers were able to compromise the login pages. When asked, a member of ShinyHunters told TechCrunch that they couldn't comment on specifics, but said this is a second, separate breach. Following the original breach at Instructure, the hackers claimed to have "
Instructure disclosed a data breach in which hackers stole students’ private information, including names, personal email addresses, and messages between teachers and students. Hackers then compromised Instructure again by defacing several schools’ login pages to the Canvas platform. Canvas is used by schools to manage coursework, assignments, and communication with students. A cybercrime group posted messages on the Canvas login pages of three schools by injecting an HTML file that altered the login screens. The message threatened to publish stolen data on May 12 unless Instructure negotiated a settlement. Instructure’s site showed partial availability and Canvas displayed scheduled maintenance. The group previously claimed responsibility for the earlier hack and used a leak site to pressure payment.
Read at TechCrunch
Unable to calculate read time
[
|
]