Smashing Security podcast #467: How ShinyHunters hacked the world’s biggest universities

Welcome to the largest educational data breach in history – affecting nearly 9,000 institutions, every

Welcome to the largest educational data breach in history – affecting nearly 9,000 institutions, every
How shiny hunters hack the world’s biggest universities with Graham Cluley and special guest Danny Palmer. Hello, hello, and welcome to Smashing Security, episode 467.
My name’s Graham Cluley.
So right now things are ramping up for Infosecurity Europe, which is in about a month’s time. And yeah, it’s getting really, really busy.
Turns out putting on a conference is a very hefty task.
There are loads of people to meet, loads of talks to see, networking, that sort of thing. And yeah, interesting keynotes this year from various people.
I’ll be seeing it from the other side of the fence this time, as it were.
So I’ll be there at the Infosecurity Magazine stand rather than just pottering around and doing what I want to do myself.
So on the Excel in the first week of June next month, I think currently the sign-up is still free. You don’t have to pay anything.
I think if you sign up after about middle of May, you have to pay the grand total of about £49 to sign up. I think it is these days.
So if you’re intrigued about that, come along and find out more. Well, before we kick off, let’s thank this week’s wonderful sponsors: Elastic, CoreView, and Vanta.
We’ll be hearing more about them later on the show.
This week on Smashing Security, we won’t be talking about the water company that failed to notice for almost two years that it had been hit by the Clop ransomware gang and how it’s now been fined almost £1 million.
You’ll hear no discussion of how a US bank has reported itself to regulators after uploading large amounts of nonpublic information about its customers to an unauthorized AI application.
And we won’t even mention how hackers are abusing Google Ads and Claude AI to push malware onto Macs. So Danny, what are you going to be talking about this week?
Plus, don’t miss our featured interview with Mike Nichols of Elastic Security on why the SOC isn’t dying, attackers and defenders are both deploying AI agents, and how the real security crisis is no longer human users, it’s the bots acting on their behalf.
All this and much more coming up in this episode of Smashing Security. This week’s episode is supported by Vanta. Joe, what’s your 2 AM security worry?
Well, enter Vanta. Vanta automates the manual misery so you can stop sweating over spreadsheets, chasing audit evidence, and filling in endless questionnaires.
That’s vanta.com/smashing. And listeners, you can get $1,000 off.
And you’ve not slept properly for about 11 days, which frankly is a bit like being a cybersecurity journalist, I think.
30 million users. There’s 8,000 institutions relying on this service. But Harvard, Princeton, Columbia, Georgetown, Duke, Virginia Tech, they all rely on Canvas.
And you log in to grab your study notes or to check your grades or to submit the assignments you finally started at 3 o’clock this morning.
And instead of your normal dashboard, what you see is a black screen rimmed in ominous red.
For them, it’s all emojis. It’s all rhubarbs or aubergines or—
I was at university at that point where it was just on the cusp of becoming digital in sort of the mid-noughties. But from what it sounds like, a lot of it is now online.
With what it sounds like a bit of a monopoly on this platform of how universities do things, which seem to have turned out not very good, it seems.
I mean, this is by some margin, apparently, the largest educational data breach in the history of educational data breaches. And there’ve been a few.
So Shiny Hunters, we always talk about Shiny Hunters.
Apparently the shiny Pokémon are the rarer Pokémon.
That is the name of a shady information sharing network in the sci-fi RPG Mass Effect. So yeah, a lot of them seem to get names from these sort of things as well.
It’s almost as if there’s a certain type of person that is engaged in this sort of activity.
Around 275 million records from nearly 9,000 institutions, not only across the United States, but the UK, Canada, Australia, New Zealand, et cetera, et cetera, including allegedly every single Ivy League university.
And it’s not just student IDs and email addresses, but there are also apparently several billions of private messages between students and teachers, which was sent via the system.
Now, I was wondering, well, what kind of messages might students have been sending their teachers and professors?
And remembering back to when I would communicate during university times, you know, I imagine there’s a fair percentage of them which are “my dog ate my homework.”
And so my assignment hasn’t been finished.
So they revoked the access, they called in forensics, digital forensics, and on May 1st, they put out one of those carefully worded statements.
If you went to the pub and said to your friends, “I was hacked by a threat actor,” they wouldn’t know what you’re talking about.
Oh, good. And two days later, they let the affected schools know about it, and they confirmed, yeah, names, emails, student ID messages got out.
Shinyhunters demanded a ransom, they gave a deadline of May 6th, basically, the usual story, which is pay up or we’re gonna leak it.
They don’t just ransom your stuff, they also will blackmail you as well, you know, because they are efficient, I guess, if you can say that.
And instead, what they did was they announced that they had deployed what they call— this is a technical term, Danny.
I know you’re a technical cybersecurity journalist, just to brace yourself for this one. They deployed what they call security patches, apparently. Have you heard of such things?
Apparently this is what they did.
But I’m not sure if that’s the response to a ransomware incident.