Data belonging to UvA students, lecturers, and staff has been stolen in a hack targeting Canvas, the digital learning environment also used by the UvA. ICT Services has confirmed the breach. It is not yet known exactly which data has been affected. As a precaution, the UvA is keeping Canvas offline. The investigation into the data breach is still ongoing. According to BNR, Dutch universities will keep their Canvas systems offline for the entire week.
A cyberattack by the hacker collective ShinyHunters – the same group previously responsible for hacking Dutch telecom provider Odido – targeted the software platform Canvas and resulted in the theft of data from UvA students and staff. The university announced this in an update on the staff website. ICT Services initially reported the breach on 5 May.
It remains unclear which specific data belonging to UvA users was involved in the hack. Instructure, the American parent company behind Canvas, is still investigating the nature and scale of the breach. On the evening of Thursday 7 May, the hacker group posted a message stating that they had regained or still had access. As a result, the UvA shut down Canvas on 8 May. On 11 May, the university announced that the system will remain offline for the time being.
According to De Telegraaf, the stolen database includes names, email addresses, student numbers, and messages exchanged between users. Passwords, birth dates, identity documents, and financial information are reportedly not among the stolen data.
The newspaper also reports that affected educational institutions have received a threatening message from ShinyHunters. Schools were allegedly “given until 7 May to negotiate with the hackers in order to prevent their data from being published on the dark web.”
Other universities
Other universities
According to the umbrella organisation Universities of the Netherlands (UNL), several other Dutch universities have also been affected, including Vrije Universiteit Amsterdam, Erasmus University Rotterdam, Tilburg University, Eindhoven University of Technology, Maastricht University, and the University of Twente. Worldwide, data from more than 275 million students, lecturers, and education staff members has reportedly been stolen.
Impact on teaching and examinations
In a statement, the UvA has announced that it is “doing everything in its power” to ensure that teaching and assessment go ahead as planned. “Scheduled teaching and examinations will take place as normal today.” With regard to completing and submitting assignments, lecturers have been asked to “be flexible regarding any deadlines”.
Faculties are working on alternatives to make study materials available for students who have exams in the coming days. Degree programmes are informing the affected students about this. On Monday morning, lecturers received an email with advice and a link to a special website from the Teaching & Learning Centre (TLC) containing more information about teaching without Canvas.
According to BNR, Dutch universities will keep their Canvas systems offline for the entire week.
Update 7 May, 12:22 – The UvA reports that the universities were not approached by the hackers to pay ransom for the data, as De Telegraaf had stated. In addition, the UvA writes that it has now filed a report with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Update: This article has been adapted on 8 May at 10.45 hours.
Update: This article has been adapted on 8 May at 13.15 hours.
Update: This article has been adapted on 11 May at 10.30 hours.
Update: This article has been adapted on 11 May at 16.45 hours.