A new incident page has been created for this event.
313 Team (yes, again) are claiming credit, but the list of impacted schools and ransom note were from ShinyHunters, so this may just be fishing for credit.
Heard some reports of phishing emails targeting users. I wrote it off because honestly, it’s not real hard to figure out email addresses for college students en masse. It really really isn’t. And it’s even easier to figure out who uses Canvas. But then…
Based on this looks like they may have also been used to serve some sort of malware, possibly a JS token stealer? I’m not familiar enough with Instructure’s actual software beyond that Canvas is browser-based and the first account popped was Discord. Definitely something to look into. I haven’t seen an uptick in compromised Discord accounts so far today but I also haven’t been paying much attention.
Not surprised. I’ve now also seen a second definite Canvas user get their Discord account stolen and used to spam ‘investment opportunities.’ I’m not in touch with the account owner, but I know they used Canvas. They complain about it constantly. So it’s definitely looking like there was more than just exfil.