PrivacySignal
Breach

The Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust Problem

DataBreaches.net · · International · Data Breaches

Months after a breach at Instructure, the company behind the Canvas learning management system, affected educational institutions are still waiting for individualized findings. As of early July, Instructure had only begun delivering the first wave of institution-specific data packets, with the forensic review dragging well past initial timelines.

Why this matters: Schools handed Instructure data on students — many of them minors — because they had no real choice. Canvas is everywhere in K-12 and higher education. When the vendor gets breached, institutions cannot fix it, investigate it, or even know what was taken without the vendor's cooperation. Months of waiting for a 'data packet' is not a security process most affected students or parents would recognize as accountability. This is what vendor lock-in looks like when something goes wrong: you wait in line to find out how badly you were exposed.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
DataBreaches.net · · International

A massive cache of Valve data has reportedly leaked online, appearing to include Portal 2’s elusive beta build and a potential weapon from Half-Life 2: Episode 3

A large cache of internal Valve data, reportedly totaling 12 terabytes, has leaked from an unknown source and is being analyzed online. The files appear to include unreleased beta builds of several classic Valve games and possible content from the long-cancelled Half-Life 2: Episode 3.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

VT: Local VA warns of possible data breach

The VA's White River Junction, Vermont healthcare facility disclosed that unencrypted communications containing veterans' personal health information were sent in error earlier this summer. The department acknowledged the incident in a public release, confirming the exposure was unintentional.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · General readers · Policy

#breach#healthcare#privacy Read original →
Breach
DataBreaches.net · · International

De: Hackers demand 30 bitcoin from Berlin as sensitive data breach widens

Hackers have demanded 30 bitcoin from the Berlin city government following a breach of its administrative data network, with the attack occurring roughly two weeks ago. Berlin officials are declining to disclose what data was accessed, who is responsible, or how they are responding to the ransom demand.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · AI governance

#breach#gdpr Read original →
Breach
DataBreaches.net · · International

US officials backpedal on claims that government agencies were hacked by Chinese

U.S. officials have walked back earlier statements claiming Chinese spies successfully hacked several government agencies, clarifying that the Senate, the Federal Reserve, NASA, and others were targeted but not confirmed as breached. The Justice Department quietly updated its language to reflect the distinction.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

PEAR leaks data allegedly exfiltrated from South Plains Rural Health Services while SPRHS remains silent

SuspectFile reports: A cyberattack against a Texas healthcare organization allegedly resulted in the exfiltration of approximately 1.4 TB of data, according to claims made by the ransomware group PEAR. The alleged victim is South Plains Rural Health Services, Inc. (SPRHS), a nonprofit healthcare organization that has provided services to rural communities across West Texas for decades. The information... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Two different groups have recently attacked Interim HealthCare entities. Should other franchises be concerned?

Two separate threat actors have attacked different Interim HealthCare franchise locations, with breaches at the West Texas and Amarillo franchises affecting nearly 2,800 patients combined and triggering federal notifications to the Department of Health and Human Services.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#enforcement Read original →