tech · HK01

Privacy Commissioner Clears Four HK Institutions After Canvas Platform Breach Affects 150,000-Plus

27 minutes ago7 MIN
Privacy Commissioner Clears Four HK Institutions After Canvas Platform Breach Affects 150,000-Plus

Summary

The Office of the Privacy Commissioner for Personal Data (PCPD) has concluded its investigation into a data breach originating from the Canvas online learning management platform, clearing all four affected Hong Kong education institutions of any violations under the Personal Data (Privacy) Ordinance. The breach, which exposed personal information of more than 150,000 individuals, resulted from vulnerabilities in the third-party platform operated by US-based Instructure Inc., rather than any failure by the local institutions. Privacy Commissioner Alice Ip Yuk-kuen determined that the institutions had conducted adequate due diligence before adopting the platform, including pre-adoption assessments, contractual safeguards, and audit mechanisms.

Key Points

  • Seven institutions initially reported potential exposure between May 6-11, 2026, but the breach ultimately affected only four: City University of Hong Kong, Hong Kong Academy for Performing Arts, Hong Kong Institute of Construction, and Hong Kong University of Science and Technology
  • City University bore the largest impact with 146,969 students and staff members' data exposed, including names, email addresses, user names, student numbers, and course enrollment information
  • The ShinyHunters hacker group first gained unauthorized access on April 29, 2026, through a "Free-For-Teacher" account on Canvas,窃取用户资料 before being blocked; hackers later exploited another vulnerability on May 7 to modify login pages with ransom messages
  • In response, Instructure patched the security vulnerabilities, disabled the "Free-For-Teacher" service, restored Canvas on May 9 after independent cybersecurity review, and reached an agreement with the hackers on May 11 to retrieve the stolen data
  • The PCPD found that the institutions' internal systems remained unaffected, and since they had conducted proper pre-adoption assessments and established contractual protections, no violation of the Personal Data (Privacy) Ordinance occurred

Why It Matters

The ruling establishes a critical precedent for Hong Kong's education sector, clarifying that institutions can avoid liability when third-party platforms are compromised provided they implement proper due diligence measures beforehand. The PCPD's accompanying recommendations—including mandatory multi-factor authentication, regular security audits of external platforms, and data minimization practices—will likely become the new standard for how universities and schools across Hong Kong manage digital learning tools going forward .
The ruling establishes a critical precedent for Hong Kong's education sector, clarifying that institutions can avoid liability when third-party platforms are compromised provided they implement proper due diligence measures beforehand. The PCPD's accompanying recommendations—including mandatory multi-factor authentication, regular security audits of external platforms, and data minimization practices—will likely become the new standard for how universities and schools across Hong Kong manage digital learning tools going forward .