Get all your news in one place.
100's of premium titles.
One app.
Start reading
Bangkok Post
Bangkok Post
World

More than 153,000 students, staff affected in Canvas data breach: privacy watchdog

The Office of the Privacy Commissioner for Personal Data has found that more than 153,000 students and staff from several Hong Kong universities were affected in the cyberattack in May. (Photo: South China Morning Post)

More than 153,000 students and staff from four tertiary institutions in Hong Kong have been affected by a data breach on the online learning management platform Canvas, an investigation by the city's privacy watchdog has found.

Nearly four months after the data breach was discovered, the Office of the Privacy Commissioner for Personal Data (PCPD) said on Thursday that the incident stemmed from "vulnerabilities relating to a third-party platform", although it did not affect the internal systems of the four institutions.

Among the at least 153,866 students and staff affected in Hong Kong, an overwhelming 96% were from City University of Hong Kong (CityU), according to the watchdog.

CityU said among its 146,969 affected accounts, around 34,000 were active accounts used by staff and students, while the remainder were inactive archived accounts.

"The data involved is strictly limited to basic identifiers such as names, student IDs and email addresses and does not involve any sensitive personal data," it said.

The Hong Kong Academy for Performing Arts had 4,584 affected students and staff, while the Hong Kong Institute of Construction had 2,333. The number for the Hong Kong University of Science and Technology was still pending verification.

The leaked personal information mainly included names of students and staff, email addresses, usernames, student IDs, course enrolment information, login IDs and messages sent by users.

"There is no evidence to suggest that the four educational institutions had failed to take all practicable steps to safeguard the personal data in their possession while using Canvas, and therefore there was no contravention of the Personal Data (Privacy) Ordinance," said Privacy Commissioner Ada Chung Lai-ling.

The watchdog noted that the affected institutions had conducted pre-assessments before deploying Canvas, adopted contractual measures and established monitoring mechanisms to safeguard the personal data transferred to Canvas.

Canvas is a web-based learning management platform operated by Instructure, which assists educational institutions, educators and students in accessing and managing online course materials, and supports skill development and learning exchange.

On May 11, the company announced that it had reached an agreement with the attacker to return all stolen data.

PCPD recommended that the educational institutions involved in the incident reassess the risks of data breaches and strengthen monitoring of the security measures implemented by third-party platforms.

They should also review and minimise the amount of personal data stored on such platforms, enable multi-factor authentication for accounts and define clear access rights and data retention periods to ensure data security, the watchdog said.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.