Hackers are threatening to leak the data of 275 million students and lecturers on Tuesday 6 May. Seven Dutch universities and at least two universities of applied sciences have also been affected. What is the danger?
Students and staff have now been informed the hack at Canvas, an online platform used by many educational institutions. As far as is known, hackers have stolen names, email addresses and student numbers, as well as messages sent within Canvas.
The hackers’ business model is simple: they demand ransom money for the information. If they do not receive payment, they publish the information on the dark web, allowing scammers to do whatever they want with it.
There are various websites explaining how phishing works. Vrije Universiteit Amsterdam (one of the affected institutions) has listed a number of warning signs on its own website.
Always pay attention to the sender, is one of the tips. The sender may call themselves ‘Administration Department’, while the email address is not from your own educational institution. Suspicious links can be checked on the website checkjelinkje.nl .
The Dutch government also has a website safe internet use . It includes a warning domains that replace, for example, the letter o with the number 0 or the letter l with the number 1. You may then see names such as h0gesch00l or Ti1burg University.
Scammers can work even more selectively by combining information from social media with leaked data. If you play korfball, for example, you may receive an email a student korfball tournament. Thanks to AI, scammers can personalise spam messages.
In any case, stay alert. To help others, you can report fake emails to the IT department of your educational institution.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
