Data breach at the Canvas learning platform
The SCK CEN Academy has been informed that user data from the online learning platform Canvas has been compromised as part of a large-scale cybersecurity incident which happened on 1 May 2026. Stakeholders have been monitoring this at different levels and necessary actions were taken.
What has happened?
The US company Instructure, the creator of Canvas, confirmed a cybersecurity incident on 1 May 2026. According to Instructure, names, email addresses, student numbers and messages between users may have been compromised. The company reports that data on passwords, dates of birth, official identity numbers or financial data are not involved. Read the full information on the website https://safeonweb.be/
What is the impact on you as a (past) participant in the training courses, events and visits organized by the SCK CEN Academy?
When you register for a training course, event or visit via the SCK CEN Academy, only your name, email and participant number is transferred towards Canvas. All other (personal) information is managed in other systems required for administration or security purposes (separated from Canvas).
If your details, such as your name, email address, participant number or messages, have indeed been compromised, criminals can use that information to create convincing phishing messages. On May 12, 2026, the SCK CEN Academy was informed that agreements have been made between Instructure and the unauthorized actor with assurances that the involved data was returned and copies were deleted.
What can you do?
We advise you to remain extra vigilant about messages purporting to come from the SCK CEN Academy, Canvas, or a lecturer.
Pay particular attention to:
-
Be wary of emails or text messages stating that you must log in immediately, ‘reactivate’ your account or make a payment quickly.
-
Do not simply click on links in messages. Go to the direct login page to access the learning environment of the SCK CEN Academy via https://sckcen.eduframe.nl.
-
The SCK CEN Academy, trainer/lecturer or helpdesk affiliated to SCK CEN will never ask you to send your password or login code.
-
Phishing can seem more credible if criminals know your name, course or participant number. Even a message containing correct personal details can be fake.
-
Do not open unexpected attachments, especially if the message is urgent or feels unusual. Do not click on suspicious links.
For more info, please contact academy [at] sckcen [dot] be (academy[at]sckcen[dot]be)