|
Welcome back to the TCE Strategy monthly newsletter! From Canvas hacks to trains being brought to a halt by a cybercriminal to the Supreme Court considering if “geowarrants” are legal, May has been a whirlwind of cybersecurity news. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.
Canvas Lets a 1-2 Punch Through Its Defenses and Was Down for the Count
Canvas (not to be confused with Canva) is a very popular Learning Management System, also known as an LMS. Between one third to half of all K-12 and higher education campuses use it, depending on which source you check. So, if a cybercriminal can exfiltrate data from Canvas or disrupt the ability to use it, the consequences would be very widespread. On April 29th, a cybercriminal gang called ShinyHunters exfiltrated data out of Canvas from 275,000,000 students at 9,000 different schools, and demanded that Canvas pay them, or else they would release the data. The cybercriminals were able to pull off this breach by manipulating a type of Canvas account called “Free-For-Teacher”. On May 1st, Canvas claimed that the incident was contained (although that claim has since been deleted from their page), but on May 7th, ShinyHunters used the same attack vector they did for the prior breach to perform a denial-of-service attack against Canvas, and the timing of this attack was not random: The timing coincides with finals week at many colleges. Here is a screenshot of the ransom note that appeared on users’ screens during the attack:

This 1-2 punch was enough to get Canvas to buckle under the pressure, so they chose to pay ShinyHunters to not leak the stolen data and to stop their denial-of-service attacks. Canvas put up a detailed account of their agreement with ShinyHunters (see the section dated 5/11/26) but the amount paid was not disclosed.
This incident has such wide-spread scope that the USA Congress has called Infrastructure (the parent company of Canvas) to testify, which is a move that is very rarely used (read: the Equifax breach of 2017). This breach now has its own Wikipedia page dedicated to it. Wow.
Takeaways: There is a lot to unpack here. First, ransomware is a preventable crime. Whatever hole existed in Canvas’s “Free-For-Teacher” accounts, it must have been very large and totally unknown to Canvas. Otherwise using that hole twice for two separate attacks just doesn’t makes sense. This points to a lack of cybersecurity testing of this part of the Canvas product. Second, organizations that depend on a certain service to perform core functions need to actively accept that their company will be shut down if that service is unavailable, or they need to have a backup plan to work around an outage such as this, especially during critical times of the year (read: finals week). Finally, while paying ShinyHunters may have prevented the data from being leaked so far, there is no honor among thieves, as this 2024 example from Change Healthcare (UHG) demonstrates.
The US Supreme Court Weighs if “Geofence warrants” are Constitutional
The Constitution states the following: “The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.” Obviously, the Founding Fathers of the USA could not have envisioned the technology available in the 21st century, which causes a need to interpret the intention of a document written 250 years ago into modern society.
Along these lines, law enforcement would like the ability to pull data in the following scenario:
-
A crime is committed. The location of the crime is known.
-
Law Enforcement does not have the names of probable suspects that may have committed the crime.
-
Instead of requesting a warrant for specific people, law enforcement wants to be able to deliver a warrant to large tech companies such as Google or Verizon to be able to search the data of all cell phones (and the names of the owners of those cell phones) within a certain geographic radius of the crime.
Please carefully read the Constitutional language above, and then re-read the request in item #3 above. Should it be allowed to vacuum up thousands of people’s names that were near, say, San Mateo, California, USA when $100 million in jewelry was stolen last year? Is that valid police work or an invasion of privacy? What does the thought of your location being used against you (with no other evidence that you were part of a crime) say about how a free society should operate? That is the question being considered by the Supreme Court. A lower court has deemed these sort of blanket searches to be unconstitutional.
Takeaways: As our technology continues to advance, the appropriate use of that technology continues to evolve, and the issue of how to apply the Constitution to new technologies is nothing new. That being said, the definition of a “free society” is in question if everyone’s location is open to law enforcement when the only probable cause is if you were in proximity to something bad that happened. While I’d like to offer up the idea of leaving your cell phone at home, doing so has been used against defendants in several cases. The biggest takeaway here is to do some genuine critical thinking on where your values stand on this issue, and vote for candidates that represent your values.
When High Speed Railway Isn’t
In a classic case of a security system being turned inside out, a Taiwanese student was arrested last month for hacking into the communication system used to control the high-speed rail trains in that country and activating the emergency brakes on four separate trains, stopping them for 48 minutes. This is not a small event – over 80 million people per year ride this rail system.
The system that the student hacked into had been in use for 19 years, meaning that the student was literally working on his potty training when this system was originally put into service. We live in a very different world than we did 19 years ago, and the cybersecurity concerns around our world are not the same as they were back then. Regrettably, the cybersecurity of this signaling system had not been improved in the last 19 years, which left it wide open for compromise.
In this case, it appears that the student was able to “clone” a legitimate transmitter for the train signaling system, and he sent a General Alarm to four trains, which is the highest level of alert that the system is designed for. The trains acted as if they received an authenticated signal to activate their emergency brakes and they stopped on the tracks.
Takeaways: The student in question is out on bail, but his life is forever changed by this foolish decision. On one hand, he hacked a system that was bound to be hacked eventually, simply because it has become so easy to do so with today’s technology. On the other hand, many systems are designed to expect well-intentioned people to run it. Cars on public roads are expected to follow certain rules to keep everyone safe. Welders using acetylene torches can very easily cut through their own air lines and create an uncontrolled blow torch, but they are trained to avoid doing that. In this case, I’m torn between blaming the student or blaming the system. When it comes to public transportation, the thought that insecure control systems could be used by an adversarial Nation State during a conflict is very reasonable. This student deserves to be punished for what he did, but at the same time, he exposed a serious flaw in a system that should have been closed years ago.
Until next month, stay safe!
|