Celebrate Excellence in Education: Nominate Outstanding Educators by April 15!
How is your institution dealing with the problem of spammers finding Canvas Catalog sites, self-registering and then self-enrolling in free open courses for the sole purpose of posting Spam messages. Originally, they were simply creating spam ePortfolios, so we had Instructure disable that functionality entirely. Then they moved on to using anything inside the free courses to post their spam — discussion boards, messages to other students, and even conference descriptions. We’ve had to essentially disable ALL forms of student collaboration or discussion in our Canvas Catalog instance.
So far, the official solution from Instructure seems to be to disable self-registration, but does that mean canceling our contracts for Canvas Catalog? The primary business purpose of Canvas Catalog *is* to enable self-registration. It is essentially a pretty, public-facing, front-door to our LMS, and the best solution from Instructure so far has been to close the door.
How are other schools handling this situation?
I'm wondering if a work-around would be to use a fee and discount code that eliminates the fee communicated on a program website. Also wondering if keeping the course unpublished and then disabling self registration after the course is live would work.
I haven't had this problem at my organization, but I think the Promotion Code idea above should work well
We had considered that option as well. However, since most likely these spammers have spreadsheets full of stolen credit cards, we are afraid that we'd just be creating a bigger hassle for ourselves with charge-backs, refunds, etc.
Hi John, We don't have this issue yet. We did have to deal with the ePortfolio pages. I am wondering if it would work to put the canvas catalog link inside your institutions internal webpages for students? Are your courses open to the general population? Also it might be too late for this if the URL is out there already.
I thought this would be helpful to this conversation: https://community.canvaslms.com/ideas/15682-include-administrative-notifications-for-eportfolio-mode...
We just got hit with over a thousand spam accounts because of free courses and now are trying to find ways to mitigate this situation. Has anybody found an effective solution? Right now I am thinking we have to eliminate usage of all free courses and create a custom registration site with captcha attached. Ideally Instructure would be using captcha on these registration pages.
Hi Chris,
After I saw your post I checked our Catalog instance. We were hit with 14,000 spam accounts. I deleted them all yesterday and now again today I have another new 6,000 spam accounts. Ours are all from @qq.com. I asked our CSM for immediate action at least on that domain. Yes captcha would be a huge help.
Wow, I thought our 1000 were bad... and yes, all ours were from @qq.com also. Good luck... I have reached out to our CSM also, as well as opened a ticket on this matter. Good luck!
I just discovered we're experiencing the same problem. However, they are not registering through Catalog. They are simply creating a profile on Canvas. The latest attack seemed to be automated. Each registration name had a time stamp at the beginning of the name. It created approximately 1250 profiles in about a minute.
To participate in the Instructure Community, you need to sign up or log in:
Sign In
This discussion post is outdated and has been archived. Please use the Community question forums and official documentation for the most current and accurate information.