Press "Enter" to skip to content

Tag: Hack

NELE: June 2026

We had a good turnout for the final NELE of the year at Northumbria. They got the ball rolling by sharing their experience of using Claude AI. While most of us are sticking to CoPilot because access is being included in our Microsoft site licenses, Northumbria have rolled out the Enterprise Pro version of Claude for all staff and students, only the 4th HEI to do so globally, and 2nd in the UK. This has been rolled out in a way that is “aligned to the university’s ethical values”, meaning that there is no training on user data, their data is isolated from the wider Claude AI, and they have integrated ‘abuse detection’ designed to stop students from asking it to write their work for them, with the big caveat that such measures can typically be circumvented by astute students (maybe they should get extra credit…).

Usage has been good, with 8,000 active users at any given time, though Andrew noted that some students are reluctant to use it because they think the university is monitoring them. Spoiler, they are, but only for safeguarding and this is made clear in their AI policy. Northumbria are also one of the few UK HEIs using Turnitin’s AI detection, with their academic community split on whether or not this is good or useful.

Next, Jean from their Library talked about assistive technology for neurodivergent students and the DSA audit which the government is currently conducting. Matching the experience of the sector, Northumbria are noting a big increase in the number of students declaring a specific learning disability, of which 44% are related to neurodivergence, and 29% to mental health. This isn’t a bad thing though. UCAS have changed how they ask students to report SpLD, moving from a medical to a social model of disability. Alas that the government hasn’t gotten that message though, and still ask students to submit multiple forms of evidence in order to be awarded DSA. Jean had a couple of students presenting with her to talk about their experience, and they spoke about how useful some of the specialist software has been for them, and how worried they are about the government’s review.

Leading on from this, Ross from Durham led our next discussion on digital accessibility. He talked about the new European Accessibility Act which, though it won’t directly apply in the UK, will still benefit us all as it applies to software vendors who are going to have to comply with these new standards. At first glance, this looks like the EU doing everyone a solid again, like forcing a charging standard and removable batteries. (Imperfect those these interventions may be, the intentions are good and generally beneficial.)

After lunch I led a discussion on Instructure’s recent Minor Security Incident and talked about how we responded at Sunderland. Newcastle’s response was broadly similar to ours, and most of us have contingency plans of some kind in place. Teesside, interestingly, have banned the use of IT related apps like Teams and Outlook on personal devices, a policy that was put in place around 18 months ago. I also know that at Durham if you want to install Outlook / Teams you have to agree to give them permission to remotely wipe your device – on Android at least, I don’t know if this is possible on iOS, outside of a fully managed device.

Next we had a demo of a virtual reality simulation Northumbria created for students to experience a police interrogation. At their Coach Lane Campus they have set up a house which can be configured to simulate different scenarios which are recorded with 360° cameras and which students can then experience in full VR using HTC Vive Focus 3 headsets. They used to do this kind of thing in a real environment, but that limits the amount of students who can be there at any one time, and requires a lot more effort to set-up and set-down. I came away from this one with a lot of ideas and new software to go and have a look at.

Finally, the day ended with a showcase of digital content created by Newcastle’s Digital Content team, which was good for me to compare with our own Showcase Module in Canvas, and gave me some ideas on how we could revamp that and make it a bit snazzier.

One last thing… like the Apple keynotes of old, I’ve saved the best news for last – NELE is getting its own website. This came out of a suggestion by one of our members who was looking for a central space for upcoming meeting dates and locations. This may also help us to reach out to FE Colleges where we have tried, but failed to get much engagement, either as NELE or ALT North East. I offered to set this up as I have the headroom to do so, and so I’ll be moving these write-ups to the new site from next year.

Leave a Comment

Instructure Pwned

Photo of a squashed Pikachu in a shop window
Slightly Squashed Pikachu. Unrelated.

So, err, Instructure have been in the news for rather unfortunate reasons. I didn’t know if I should say anything about this, but of course my team and I have been keep busy by it, and I have some thoughts on the situation, so first I’ll reiterate that this is my personal blog, and is in no way affiliated with, and my views are not endorsed by the University of Sunderland, or Instructure. Necessarily.

The purveyors of Canvas, Sunderland’s VLE for the past decade or thereabouts, were hacked on the 25th of April. They didn’t discover the intrusion until the 29th, and we didn’t know until we came back from the bank holiday Monday. It did explain all the alerts sitting in my mailbox from the weekend though. In the four days that the hackers were in, they extracted data from almost 9,000 institutions using Canvas, which included names, email addresses, student IDs, and ‘messages’. 275 million individual users, between 3 and 6 terabytes of data, according to different sources. That’s a lot of damage! The largest educational security breach in history according to the Wikipedia article on the topic. (So big it has a Wikipedia article.)

Instructure believed that they had resolved the incident and refused to pay the initial ransom* demand, but after the deadline passed the hacking group got in again on May 6th/7th and placed a warning message on the Canvas homepages of around 330 institutions (but no additional data was stolen). At that point Instructure took the entire service offline while they fixed that, and subsequently paid the ransom demand in an attempt to fully resolve the situation and restore trust and confidence in Canvas.

Of course Sunderland have been affected, and in due course we’ll be getting an individualised report on exactly what data of ours was included in the breach. We were initially frustrated by what we saw as a lack of response and clear communication from Instructure, but they have responded to that feedback well, acknowledging that they were flooded with enquiries in the initial aftermath and simply couldn’t keep up. And of course they had a lot of work to do to secure their systems before being able to share specific details with their partners. We know now that the attackers used Instructure’s Free-for-Teachers platform and cross-site scripting to gain access to their backend support systems. Free-for-Teachers remains offline, but the core Canvas system is back and fully operational, and complete downtime was limited to only 8 hours or so during the second attack, and this was overnight in the UK so we were minimally affected. I’ve been on a number of calls and webinars about the incident, of course, and I’m quite confident that Instructure have fortified their security across the board to minimise any further attack opportunities.

What I’m less confident about was the wisdom of paying the ransom, for “once you have paid him the Danegeld / You never get rid of the Dane”, as Kipling put it. Of course I’m not a lawyer, or a cybersecurity boffin, and I’m certain that this was an extremely difficult and complex decision for Instructure. However, as well as the moral principle of not paying ransom, there are very strong practical reasons why you shouldn’t, namely that you can’t trust criminals! Even Instructure’s own statement on the matter included a very large caveat that the hacking group could not be trusted, and they couldn’t be completely certain that the stolen data was destroyed, as claimed. The Reg published a great article on the fallout of the attack in which they explain this very well:

“CrowdStrike surveyed 1,100 global security leaders last summer, and of the 78 percent who said they experienced a ransomware attack in the past year, 83 percent of those that paid ransoms were attacked again. Plus 93 percent lost data regardless of payment.”

As a result, my concern is that this isn’t actually over, and has the potential to reappear further down the road. Had Instructure not paid, the data would have been leaked on the dark web, and it would have been very bad for everyone involved, but from that point I feel like we could all have rebuilt and recovered. Instead we may have a sword of Damocles hanging over us.

It’s a sad state of affairs that in the world we’ve built this is a common occurrence. Everyone gets hacked. Sunderland itself were hacked back in 2021 in what we now refer to as ‘the cyber security incident’. Part of the problem is that we’ve all outsourced data into huge silos managed by a small handful of tech giants. When I began my career, long, long ago, we ran Blackboard on our own servers. Our data, managed by the university, in a server room on campus with a mirrored offsite backup. It’s an approach that had its advantages. While I’m sympathetic towards Instructure, and I think they’re less likely to suffer from future incidents as a result of the security hardening measures they’ve put in place, I know that there are institutions who have already spun up a Moodle server almost overnight and moved away, possibly permanently. We’ve made our own contingency plans at Sunderland which I won’t talk about, and I’m looking forward to NELE in a few weeks to gossip with the gang and find out more about how Newcastle have handled things.

Something useful that I learned was that Jisc in the UK are constantly monitoring the dark web looking for evidence of data leaks which may affect any institution, and Instructure have contracted with a security agency who are doing the same thing on their behalf as part of their response to the incident.

More and up to date information is available on Instructure’s Incident Update webpage.

* These kind of attacks are called ‘ransomware’, but as a Reg Commentator commented, it would be more accurate to call this kind of attack blackmail.

Leave a Comment