Plain English Summary and Action Plan for Parents The recent security breach of the Canvas platform by the hacker group ShinyHunters is a significant event. In simple terms, hackers gained access to the system because of a weak link in a connected service (a third-party tool used for data monitoring). While the hackers did not get credit card numbers or Social Security numbers in this specific attack, they did steal names, email addresses, student ID numbers, and private messages sent within the Canvas system. This information is often used by criminals to create very convincing "phishing" scams—fake emails or messages designed to trick students into giving up their passwords or downloading viruses. Because many of these students are at major research universities, there is also a concern that hackers might try to use these stolen messages to get access to valuable research data or school projects. Immediate Steps for Parents and Students If your student uses Canvas, you should take the following steps immediately to protect their digital identity and academic work. Change Passwords and Enable MFA (The Most Important Step) For the Student: Change the Canvas password immediately. If they use that same password for their email, social media, or bank accounts, they must change those as well. The Rule: Never reuse the same password across different sites. Use a Password Manager (like iCloud Keychain, 1Password, or Bitwarden) to create and store strong, unique passwords. Enable MFA: Ensure Multi-Factor Authentication (MFA)—where you have to approve a login on your phone—is turned on for their school account and their personal email. Scrub Private Messages For the Student: Remind them that the "Inbox" feature in Canvas is not a secure or private chat room. Action: If they have sent sensitive information (like passwords, photos of IDs, or proprietary research ideas) via Canvas messages, they should assume that information is now in the hands of hackers and take steps to cancel those IDs or change those passwords. Practice "Extreme Skepticism" with Emails The Threat: Hackers now have your student’s name and school ID. They might send an email that looks like it’s from "The University IT Department" or a specific professor, asking the student to "click here to verify your account." The Advice: Tell your kids: Never click links in an email regarding account security. If they get an alert, they should go directly to the school’s website by typing the address into their browser manually. Monitor for "Identity Ghosting" On Their Behalf: Since student IDs were stolen, hackers might try to impersonate students to gain access to campus buildings or library resources. Action: Check the student's school account activity for any weird logins or "authorized devices" they don't recognize. If the school offers an identity theft monitoring service (like LifeLock or Experian) for free following this breach, sign up for it immediately. Secure Research and Intellectual Property For College Students: If your child is involved in high-level research or a senior capstone project, they should move all sensitive discussions and files out of Canvas and into the university’s approved, encrypted storage systems (like a secure OneDrive or Google Research Drive). The Advice: Assume that any "private" message sent in Canvas before May 2026 could be read by a stranger. Update Software Action: Ensure your student’s laptop and phone are running the latest operating system updates. Hackers often use "entry points" from one breach to try and find older, unpatched security holes in a student's personal devices.