Skip to content

Instantly share code, notes, and snippets.

@grillermo
Last active August 29, 2015 14:01
Show Gist options
  • Save grillermo/f48393b01e4a6672cbe8 to your computer and use it in GitHub Desktop.
Save grillermo/f48393b01e4a6672cbe8 to your computer and use it in GitHub Desktop.
Canvas email on their Amazon account compromised
<div style='max-width: 400px'>
Canvasaurs,
We were recently made aware of a security breach that affected all of our servers hosted with Amazon, which includes the ones that previously hosted Canvas. The person(s) used our account to order hundreds of expensive servers, likely to mine Bitcoin or other cryptocurrencies. When we detected this activity, we immediately locked down the account.
Unfortunately we have no way of knowing what, if any, information was accessed by the attacker(s). It’s possible they only used our account to order servers, however it’s also possible they accessed our database, and thus user e-mail addresses, encrypted passwords, and other information.
We’d suggest you consider changing your e-mail account password, and the passwords of any services you connected with Canvas. Although Canvas account passwords were encrypted in our database using a modern, secure method called bcrypt, it’s better to be safe than sorry. To reiterate, we found no evidence of an attack targeting Canvas or its users directly, but since we’re unable to conduct a thorough investigation, we can’t know for sure what was accessed.
We’re extremely sorry this happened, and will do our best to ensure no further breaches occur.
—Team Canvas
</div>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment