More than 150,000 students and staff of four educational institutions were affected by a data breach on the online learning platform Canvas, an investigation by the Office of the Privacy Commissioner for Personal Data has found.
The breach, discovered by platform operator Instructure on April 29, involved a hacking group using a "Free-For-Teacher" account to exploit a cross-site scripting vulnerability. The cyberattack exfiltrated personal data including names, email addresses, usernames, and student IDs.
The seven institutions that initially reported possible breaches were City University, the Hong Kong Academy for Performing Arts (HKAPA), the Hong Kong Institute of Construction (HKIC), the Hong Kong University of Science and Technology, Hong Kong Art School, Polytechnic University, and Hong Kong Education City. However, investigations found only four – CityU, HKAPA, HKIC and HKUST – were actually affected.
CityU reported 146,969 students and staff had data exposed, while HKAPA had about 4,584 and HKIC around 2,333. HKUST data is still pending verification.
Privacy Commissioner Ada Chung said on Thursday that the affected institutions had conducted pre-assessments before deploying Canvas, adopted contractual safeguards, and established monitoring mechanisms.
"There is no evidence to suggest that the four educational institutions had failed to take all practicable steps to safeguard the personal data in their possession while using Canvas," Chung said in a statement.
She concluded there was no breach of the Personal Data (Privacy) Ordinance.
The commissioner urged organisations to conduct due diligence on data processors, regulate them through contracts, and enable security features like multi-factor authentication.
Edited by Aaron Tam
