×

children’s smartwatches and aftermarket vehicle accessories are riddled with security vulnerabilities that leave kids and drivers susceptible to hacking and tracking. But the sheer number of different brands and models of those devices has often made identifying the truly insecure gadgets feel nearly impossible for consumers.

#Hackers #Stalked #Hijacking #Smartwatch #Kidsgps,surveillance,hacks,privacy,security,cybersecurity,smartwatch,black hat,defcon"> Hackers Stalked Me by Hijacking a Smartwatch for KidsThe watch’s insecurity and the spying it enabled might be expected given the gadget’s pedigree: It’s sold by an obscure company called CJC, costs less than , and was made by an equally obscure manufacturer, YiQingTeng Electronics, in Shenzhen, China. More troubling, perhaps, is that the online platform it’s built on—and the one that allowed Stykas and Solferini to so thoroughly hack it—is used by dozens of other brands of smartwatch, many of which have likely been left vulnerable to the same forms of digital stalking.At the Black Hat cybersecurity conference today, Stykas and Solferini plan to present their findings from analyzing the supply chain and security of more than 70 GPS-enabled watches and car accessories. They found that more than 30 of those geolocation devices use the technology and backend servers of YiQingTeng, also identified by the brand name Wonlex, the name of a partner firm Shenzhen 3G Electronics, or their associated app, SETracker. Another 30-plus brands of tracking devices for cars and kids are all run on another Shenzhen-based platform known as NewGPS2012.Combined with another major GPS platform known as SinoTrack that sells car trackers and smartwatches, the two researchers found that tens of millions of GPS tracker gadgets came from just three supply chains. All three, the researchers found in their analysis, had significant security flaws—in some cases as simple as a lack of authentication that allowed anyone to access any device—leaving children’s watches vulnerable to tracking by a hacker, location disabling and spoofing, interception and spoofing of text and audio messages sent to them, replacement of emergency contacts with ones a hacker chose, silent audio eavesdropping, as well as photo and video capture for camera-enabled devices. (Once the GPS started working on the smartwatch WIRED tested, the hackers showed that feature, too, could be hijacked to follow the wearer’s every move.)For some GPS-enabled car accessories, the researchers found they could similarly track the devices’ locations or spoof messages to them that could potentially unlock or disable cars, though the researchers didn’t go so far as to test this out on actual vehicles. They also say they found server-side vulnerabilities that exposed consumer information, would have allowed them to execute their own code on the servers, or even in one case appeared to show that someone else had already gained unauthorized access to the system’s backend.“Millions of kids are being exposed and vulnerable to exploitation. It’s just catastrophic. It’s really low-hanging fruit for a lot of bad actors,” Stykas says. “Your criminal mind is the only limitation in exploiting those devices.”The Watches Watching Your KidsThe researchers say they’ve been warning the companies behind all three Shenzhen-based GPS platforms about their vulnerabilities for months. When WIRED reached a representative of SETracker, the person initially claimed in an email that “the issues you mentioned have been resolved long before,” adding that “we attach great importance to the security of Setracker and keep strengthening its security continuously.” When WIRED pointed out that researchers had been able to hack a smartwatch running on SETracker just this week, the person repeated their claim that the issues had been fixed, then asked for evidence of the exploitation, which WIRED provided.Only today, hours before the researchers’ talk at Black Hat, did the researchers find that their hacking techniques against SETracker’s platform have stopped working—though they’re still not sure if the flaws they found are fully fixed.Sinotrack and the NewGPS2012 platform didn’t respond to WIRED’s requests for comment, and the researchers say their hacking techniques against those systems still appear to work.For more than a decade, cybersecurity experts and privacy advocates have warned that cheap, GPS-enabled children’s smartwatches and aftermarket vehicle accessories are riddled with security vulnerabilities that leave kids and drivers susceptible to hacking and tracking. But the sheer number of different brands and models of those devices has often made identifying the truly insecure gadgets feel nearly impossible for consumers.#Hackers #Stalked #Hijacking #Smartwatch #Kidsgps,surveillance,hacks,privacy,security,cybersecurity,smartwatch,black hat,defcon
Tech-news

children’s smartwatches and aftermarket vehicle accessories are riddled with security vulnerabilities that leave kids and drivers susceptible to hacking and tracking. But the sheer number of different brands and models of those devices has often made identifying the truly insecure gadgets feel nearly impossible for consumers.

#Hackers #Stalked #Hijacking #Smartwatch #Kidsgps,surveillance,hacks,privacy,security,cybersecurity,smartwatch,black hat,defcon">Hackers Stalked Me by Hijacking a Smartwatch for Kids

The watch’s insecurity and the spying it enabled might be expected given the gadget’s pedigree: It’s sold by an obscure company called CJC, costs less than $30, and was made by an equally obscure manufacturer, YiQingTeng Electronics, in Shenzhen, China. More troubling, perhaps, is that the online platform it’s built on—and the one that allowed Stykas and Solferini to so thoroughly hack it—is used by dozens of other brands of smartwatch, many of which have likely been left vulnerable to the same forms of digital stalking.

At the Black Hat cybersecurity conference today, Stykas and Solferini plan to present their findings from analyzing the supply chain and security of more than 70 GPS-enabled watches and car accessories. They found that more than 30 of those geolocation devices use the technology and backend servers of YiQingTeng, also identified by the brand name Wonlex, the name of a partner firm Shenzhen 3G Electronics, or their associated app, SETracker. Another 30-plus brands of tracking devices for cars and kids are all run on another Shenzhen-based platform known as NewGPS2012.

Combined with another major GPS platform known as SinoTrack that sells car trackers and smartwatches, the two researchers found that tens of millions of GPS tracker gadgets came from just three supply chains. All three, the researchers found in their analysis, had significant security flaws—in some cases as simple as a lack of authentication that allowed anyone to access any device—leaving children’s watches vulnerable to tracking by a hacker, location disabling and spoofing, interception and spoofing of text and audio messages sent to them, replacement of emergency contacts with ones a hacker chose, silent audio eavesdropping, as well as photo and video capture for camera-enabled devices. (Once the GPS started working on the smartwatch WIRED tested, the hackers showed that feature, too, could be hijacked to follow the wearer’s every move.)

For some GPS-enabled car accessories, the researchers found they could similarly track the devices’ locations or spoof messages to them that could potentially unlock or disable cars, though the researchers didn’t go so far as to test this out on actual vehicles. They also say they found server-side vulnerabilities that exposed consumer information, would have allowed them to execute their own code on the servers, or even in one case appeared to show that someone else had already gained unauthorized access to the system’s backend.

“Millions of kids are being exposed and vulnerable to exploitation. It’s just catastrophic. It’s really low-hanging fruit for a lot of bad actors,” Stykas says. “Your criminal mind is the only limitation in exploiting those devices.”

The Watches Watching Your Kids

The researchers say they’ve been warning the companies behind all three Shenzhen-based GPS platforms about their vulnerabilities for months. When WIRED reached a representative of SETracker, the person initially claimed in an email that “the issues you mentioned have been resolved long before,” adding that “we attach great importance to the security of Setracker and keep strengthening its security continuously.” When WIRED pointed out that researchers had been able to hack a smartwatch running on SETracker just this week, the person repeated their claim that the issues had been fixed, then asked for evidence of the exploitation, which WIRED provided.

Only today, hours before the researchers’ talk at Black Hat, did the researchers find that their hacking techniques against SETracker’s platform have stopped working—though they’re still not sure if the flaws they found are fully fixed.

Sinotrack and the NewGPS2012 platform didn’t respond to WIRED’s requests for comment, and the researchers say their hacking techniques against those systems still appear to work.

For more than a decade, cybersecurity experts and privacy advocates have warned that cheap, GPS-enabled children’s smartwatches and aftermarket vehicle accessories are riddled with security vulnerabilities that leave kids and drivers susceptible to hacking and tracking. But the sheer number of different brands and models of those devices has often made identifying the truly insecure gadgets feel nearly impossible for consumers.

#Hackers #Stalked #Hijacking #Smartwatch #Kidsgps,surveillance,hacks,privacy,security,cybersecurity,smartwatch,black hat,defcon

The watch’s insecurity and the spying it enabled might be expected given the gadget’s pedigree:…

apps abound, all to help you stave off the many distractions coming from your phone. Or the annoying people at your open-office desk. Digital well-being tools can silence notifications, limit apps like TikTok and Instagram, and help you focus on the task at hand. But you can also turn them off very easily as soon as you feel like you haven’t endlessly scrolled enough.

This is where Flipper’s Busy Bar comes in, a hardware clock with an LED screen that doubles as a clock and a dedicated timer. Slap the big button in the middle, and the screen displays a bright red “BUSY” sign or another message that lets the people around you know you’re, well, busy. (Maybe try “GO AWAY” or “GET OUT OF MY ROOM, MOM.”) The bar goes on sale today and costs $249.

“How do you let people know politely, yet firmly, that you don’t want to be disturbed?” says Callum Tennent, a creative writer at Flipper. “We decided the politest way to do it was a massive red light on your desk.”

Image may contain Computer Hardware Electronics Hardware Monitor Screen Mobile Phone and Phone

Courtesy of Flipper Devices

Flipper Devices made the Flipper Zero, a $200 portable hacking tool that got big on TikTok in 2022 for using a Tamagotchi-esque dolphin character to detect wireless frequencies and potentially break RFID-controlled locks. It was a device that raised a variety of security concerns. Canada proposed a ban on the device out of fear that it might enable car thefts. In 2023, the US Customs and Border Protection seized 15,000 Flipper Zero devices, then ultimately released them. Flipper is currently working on another model, the Flipper One, that has even more advanced capabilities.

In between those more controversial devices comes the Busy Bar. The bar also works with the separate Busy app, yet another one of those productivity and focus tools living on your phone. What it doesn’t have is the capability of hacking anything. “It’s being made by us here at Flipper, but there’s no real connection to them,” Tennent says. “They’re totally disconnected products.”

Fundamentally, the Busy Bar is a pricey “On Air” light. It offers many of the same productivity capabilities that are likely already baked into your phone’s operating system—like blocking notifications on your phone. But Flipper is making the case that—much like the Brick, a hardware gadget you tap to block access to certain apps—having a hardware option to shut off the distractions around you is meaningfully different than just trying to use software productivity tools on your device.

#Busy #Bar #Gadget #People #Leavehacks,gadgets,smart home,apps,distractions,productivity,design"> The Busy Bar Is a Gadget to Get People to Leave You AloneFocus and productivity apps abound, all to help you stave off the many distractions coming from your phone. Or the annoying people at your open-office desk. Digital well-being tools can silence notifications, limit apps like TikTok and Instagram, and help you focus on the task at hand. But you can also turn them off very easily as soon as you feel like you haven’t endlessly scrolled enough.This is where Flipper’s Busy Bar comes in, a hardware clock with an LED screen that doubles as a clock and a dedicated timer. Slap the big button in the middle, and the screen displays a bright red “BUSY” sign or another message that lets the people around you know you’re, well, busy. (Maybe try “GO AWAY” or “GET OUT OF MY ROOM, MOM.”) The bar goes on sale today and costs 9.“How do you let people know politely, yet firmly, that you don’t want to be disturbed?” says Callum Tennent, a creative writer at Flipper. “We decided the politest way to do it was a massive red light on your desk.”Courtesy of Flipper DevicesFlipper Devices made the Flipper Zero, a 0 portable hacking tool that got big on TikTok in 2022 for using a Tamagotchi-esque dolphin character to detect wireless frequencies and potentially break RFID-controlled locks. It was a device that raised a variety of security concerns. Canada proposed a ban on the device out of fear that it might enable car thefts. In 2023, the US Customs and Border Protection seized 15,000 Flipper Zero devices, then ultimately released them. Flipper is currently working on another model, the Flipper One, that has even more advanced capabilities.In between those more controversial devices comes the Busy Bar. The bar also works with the separate Busy app, yet another one of those productivity and focus tools living on your phone. What it doesn’t have is the capability of hacking anything. “It’s being made by us here at Flipper, but there’s no real connection to them,” Tennent says. “They’re totally disconnected products.”Fundamentally, the Busy Bar is a pricey “On Air” light. It offers many of the same productivity capabilities that are likely already baked into your phone’s operating system—like blocking notifications on your phone. But Flipper is making the case that—much like the Brick, a hardware gadget you tap to block access to certain apps—having a hardware option to shut off the distractions around you is meaningfully different than just trying to use software productivity tools on your device.#Busy #Bar #Gadget #People #Leavehacks,gadgets,smart home,apps,distractions,productivity,design
Tech-news

apps abound, all to help you stave off the many distractions coming from your phone. Or the annoying people at your open-office desk. Digital well-being tools can silence notifications, limit apps like TikTok and Instagram, and help you focus on the task at hand. But you can also turn them off very easily as soon as you feel like you haven’t endlessly scrolled enough.

This is where Flipper’s Busy Bar comes in, a hardware clock with an LED screen that doubles as a clock and a dedicated timer. Slap the big button in the middle, and the screen displays a bright red “BUSY” sign or another message that lets the people around you know you’re, well, busy. (Maybe try “GO AWAY” or “GET OUT OF MY ROOM, MOM.”) The bar goes on sale today and costs $249.

“How do you let people know politely, yet firmly, that you don’t want to be disturbed?” says Callum Tennent, a creative writer at Flipper. “We decided the politest way to do it was a massive red light on your desk.”

Image may contain Computer Hardware Electronics Hardware Monitor Screen Mobile Phone and Phone

Courtesy of Flipper Devices

Flipper Devices made the Flipper Zero, a $200 portable hacking tool that got big on TikTok in 2022 for using a Tamagotchi-esque dolphin character to detect wireless frequencies and potentially break RFID-controlled locks. It was a device that raised a variety of security concerns. Canada proposed a ban on the device out of fear that it might enable car thefts. In 2023, the US Customs and Border Protection seized 15,000 Flipper Zero devices, then ultimately released them. Flipper is currently working on another model, the Flipper One, that has even more advanced capabilities.

In between those more controversial devices comes the Busy Bar. The bar also works with the separate Busy app, yet another one of those productivity and focus tools living on your phone. What it doesn’t have is the capability of hacking anything. “It’s being made by us here at Flipper, but there’s no real connection to them,” Tennent says. “They’re totally disconnected products.”

Fundamentally, the Busy Bar is a pricey “On Air” light. It offers many of the same productivity capabilities that are likely already baked into your phone’s operating system—like blocking notifications on your phone. But Flipper is making the case that—much like the Brick, a hardware gadget you tap to block access to certain apps—having a hardware option to shut off the distractions around you is meaningfully different than just trying to use software productivity tools on your device.

#Busy #Bar #Gadget #People #Leavehacks,gadgets,smart home,apps,distractions,productivity,design">The Busy Bar Is a Gadget to Get People to Leave You Alone

Focus and productivity apps abound, all to help you stave off the many distractions coming from your phone. Or the annoying people at your open-office desk. Digital well-being tools can silence notifications, limit apps like TikTok and Instagram, and help you focus on the task at hand. But you can also turn them off very easily as soon as you feel like you haven’t endlessly scrolled enough.

This is where Flipper’s Busy Bar comes in, a hardware clock with an LED screen that doubles as a clock and a dedicated timer. Slap the big button in the middle, and the screen displays a bright red “BUSY” sign or another message that lets the people around you know you’re, well, busy. (Maybe try “GO AWAY” or “GET OUT OF MY ROOM, MOM.”) The bar goes on sale today and costs $249.

“How do you let people know politely, yet firmly, that you don’t want to be disturbed?” says Callum Tennent, a creative writer at Flipper. “We decided the politest way to do it was a massive red light on your desk.”

Image may contain Computer Hardware Electronics Hardware Monitor Screen Mobile Phone and Phone

Courtesy of Flipper Devices

Flipper Devices made the Flipper Zero, a $200 portable hacking tool that got big on TikTok in 2022 for using a Tamagotchi-esque dolphin character to detect wireless frequencies and potentially break RFID-controlled locks. It was a device that raised a variety of security concerns. Canada proposed a ban on the device out of fear that it might enable car thefts. In 2023, the US Customs and Border Protection seized 15,000 Flipper Zero devices, then ultimately released them. Flipper is currently working on another model, the Flipper One, that has even more advanced capabilities.

In between those more controversial devices comes the Busy Bar. The bar also works with the separate Busy app, yet another one of those productivity and focus tools living on your phone. What it doesn’t have is the capability of hacking anything. “It’s being made by us here at Flipper, but there’s no real connection to them,” Tennent says. “They’re totally disconnected products.”

Fundamentally, the Busy Bar is a pricey “On Air” light. It offers many of the same productivity capabilities that are likely already baked into your phone’s operating system—like blocking notifications on your phone. But Flipper is making the case that—much like the Brick, a hardware gadget you tap to block access to certain apps—having a hardware option to shut off the distractions around you is meaningfully different than just trying to use software productivity tools on your device.

#Busy #Bar #Gadget #People #Leavehacks,gadgets,smart home,apps,distractions,productivity,design

Focus and productivity apps abound, all to help you stave off the many distractions coming…

gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities"> The Canvas Hack Is a New Kind of Ransomware DebacleHigher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities
Tech-news

gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities">The Canvas Hack Is a New Kind of Ransomware Debacle

Higher education has long been a target of ransomware gangs and data extortion attacks. But never before, perhaps, has a cyberattack against a single software platform so thoroughly disrupted the daily operations of thousands of schools across the United States.

The widely used digital learning platform Canvas was put into “maintenance mode” on Thursday after its maker, the education tech giant Instructure, suffered a data breach and faced an extortion attempt by attackers using the recognizable moniker “ShinyHunters.” Though the hackers have been advertising the breach and attempting to extract a ransom payment from Instructure since May 1, the situation took on additional immediacy for regular people across the US and beyond on Thursday because the Canvas downtime caused chaos at schools, including those in the midst of finals and end-of-year assignments.

Universities like Harvard, Columbia, Rutgers, and Georgetown sent alerts to students about the situation in recent days; other institutions, including school districts in at least a dozen states, also appear to have been affected. In a list published by the hackers behind the attack on their ransom-focused dark web site, they claim the breach affected more than 8,800 schools. The exact scale and reach of the breach is currently unclear, though. And the fact that Canvas was down throughout Thursday afternoon and evening further complicated the picture.

In a running incident update log that began on May 1, Steve Proud, Instructure’s chief information security officer, said that the company had “recently experienced a cybersecurity incident perpetrated by a criminal threat actor.” He added on May 2 that “the information involved” for “users at affected institutions” included names, email addresses, student ID numbers, and messages exchanged by users on the platform.

The situation was ultimately marked as “Resolved” on Wednesday, with Proud writing that “Canvas is fully operational, and we are not seeing any ongoing unauthorized activity.” At midday on Thursday, though, the Instructure status page registered an “issue” where “some users are having difficulties logging into Student ePortfolios.” Within a few hours, the company had added another status update: “Instructure has placed Canvas, Canvas Beta and Canvas Test in maintenance mode.” Late Thursday evening, the company said that Canvas was available again “for most users.”

TechCrunch reported on Thursday that the hackers launched a secondary wave of attacks, defacing some schools’ Canvas portals by injecting an HTML file to display their own message on the schools’ Canvas login pages. According to The Harvard Crimson, attackers modified the Harvard Canvas login page to show a message that included a list of schools that the hackers claim were impacted by the breach.

The message from attackers “urged schools included on the affected list to consult with a cyber advisory firm and contact the group privately to negotiate a settlement before the end of the day on May 12—or else risk their data being leaked,” The Crimson reported. “It is unclear what information tied to Harvard affiliates was included in the alleged breach.”

Instructure did not immediately respond to a request for comment about Thursday’s outages and how they fit into the bigger picture of the breach. But the situation is significant given that a massive trove of student information has potentially been exposed, and the visibility of the incident across the country makes it a key example of a longstanding, yet endlessly escalating problem of data extortion and ransomware attacks.

The ShinyHunters name is associated with massive data dumps and has been linked to the infamous hacker collective known as the Com. But as the constellation of actors has shifted over the years, numerous attackers have taken up the most prominent Com-related monikers. A number of recent attacks have invoked other names, such as Lapsus$, with little or no connection to the original group that operated under the name.

#Canvas #Hack #Kind #Ransomware #Debacleransomware,cybersecurity,malware,hacks,hacking,security,vulnerabilities

Higher education has long been a target of ransomware gangs and data extortion attacks. But…

Tech-news

Take a photo on any digital camera or smartphone and it's not just the pixels…

Tech-news

Security researchers have identified a suite of powerful hacking tools capable of compromising iPhones running…

Hollywood news

HBO is serving up a bevy of new shows in 2026, including the long-awaited follow…

Tech-news

Thousands of networks—many of them operated by the US government and Fortune 500 companies—face an…

Tech-news

Since launching its bug bounty program nearly a decade ago, Apple has always touted notable…

Tech-news

Sextortion-based hacking, which hijacks a victim's webcam or blackmails them with nudes they're tricked or…