KNOXVILLE, Tenn. — A cybersecurity incident with the Canvas learning platform vendor may have caused some users to see an unauthorized message after logging in. Knox County Schools said its technology department is working with Instructure, the Canvas vendor, and has already deleted the message. KCS said it wasn't the only school district affected. "We're probably in the same position waiting as a lot of institutions of higher ed and other school systems are waiting at this point," Jon Rysewyk, KCS Superintendent, said. "We've done everything we can on our end to be as secure as possible, so now we just kind of wait and see what our vendor will do." Instructure, the company that runs the Canvas learning management system used by more than 7,000 universities, K-12 districts and education ministries worldwide, disclosed the breach to affected institutions this week. The company confirmed names, email addresses, student ID numbers and private messages between users had been accessed before the breach was contained. The criminal extortion group ShinyHunters claimed responsibility for the attack. On a dark web leak site, the group alleged it had stolen more than 3.65 terabytes of data and threatened to release it unless its demands were met. The group said it stole roughly 275 million records tied to students, teachers and staff, and shared a list of 8,809 school districts, universities and online education platforms it claims were affected. The University of Tennessee said in a statement they do not know when Canvas services will be restored, but Instructure posted a status page to share updates on the outage. The University of Tennessee sent out the following statement. Related to this incident, Instructure has notified the Office of Innovative Technologies (OIT) of a data breach associated with some accounts. Based on what Instructure has found to