The District’s ITS team has completed the steps necessary to safely re-enable Canvas access and has implemented additional security measures consistent with the State Chancellor’s Office recommendations. While all students and employees have access, some features may be restricted or limited as ITS works to restore full functionality throughout the day.
The State Chancellor’s Office has reviewed information provided directly by Instructure and determined that Canvas does not pose an ongoing technical risk to campus platforms or student information systems.
What you should do
- Be alert to phishing attempts and suspicious messages referencing Canvas, including emails or Canvas messages from unfamiliar users soliciting money or asking you to click links.
- If you have not yet reset your OneLogin password, please do so now at this link to how to reset/change your OneLogin password.
- Report any suspicious messages or account activity to ITS through Zendesk (students) or the ITS Help Desk (employees)
What happened
The May 7 extortion message posted within Canvas was an escalation of an earlier incident. The threat actor exploited a vulnerability in “Free-for-Teacher” accounts to inject the message. That vulnerability has been identified and remediated by Instructure, and those accounts have been shut down. The attacker did not gain access to core Canvas functionality, and there were no changes to user data, grades, or assignment information.
However, some user data is believed to have been exfiltrated in the earlier incident and may be misused over time. Please remain cautious.
Where to find updates
After all features have been fully restored, a final update will be posted to alerts.smccd.edu. For statewide information on the Canvas incident, visit the CCC Security Center.