Cyber Incident Victim: Creator Studio Pro
Date:
Feb 2024
Location:
Canada
Summary
Edge Imaging reported that a third‑party yearbook software provider, Creator Studio Pro, experienced a ransomware attack after a developer credential was compromised on its Canadian AWS server, leading to the removal of raw photo files uploaded by schools for recent yearbooks. The attacker did not access any personal identifiers such as names, grades or school details, and the photos were later recovered with a commitment from the threat actor that they were deleted and not shared. The organization notified affected school boards, privacy commissioners and law enforcement, while the provider took the server offline, rotated credentials, removed developer access and engaged a security audit to strengthen protections.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On February 5, 2024, Entourage, the owner of the Creator Studio Pro yearbook software platform, detected a cyber incident on its Canadian AWS cloud server after discovering that a developer username and password for one of its server accounts had been compromised. The compromised credentials allowed a threat actor to gain access to a storage container containing yearbook photos and to remove those images in a ransomware‑style attack. Edge Imaging learned of the incident through its subcontractor relationship and, on February 8, 2024, reported the breach to the FBI, noting that Entourage is based in New Jersey and therefore falls under federal jurisdiction. Edge Imaging also notified federal and provincial privacy commissioners on February 15, 2024 and began informing affected school boards, privacy officers, primary account contacts and yearbook advisors on the same day, asking them to share the details with their school communities.

The incident affected photos that had been uploaded to Creator Studio Pro for the 2022/23 and 2023/24 school years, which Edge Imaging stated were the only data potentially accessed in the breach. According to Entourage’s assessment, the photos were raw files that did not contain names, grades, school identifiers, captions or other personal information, although some metadata such as geo‑location could be present depending on the device used to capture the images. Edge Imaging confirmed that its own IT systems were not accessed and that the broader Creator Studio Pro database, which includes page templates, text and account information, remained untouched. Six schools within the Upper Grand District School Board—Centennial CVI, Guelph CVI, Wellington Heights SS, Centre Dufferin DHS, Edward Johnson PS and Ken Danby PS—were identified as having yearbook photos stored on the affected server.
By February 29, 2024, Entourage’s cyber security advisors had negotiated the return of all Canadian photo files from the threat actors and obtained a commitment that the images had been deleted and not distributed, after which Edge Imaging began coordinating with schools to re‑upload the photographs for the yearbooks. In response to the breach, Entourage took the affected AWS cloud server offline, rotated all credentials, removed developer access to the Canadian environment unless they were working on fixes, engaged a security audit firm to review and monitor the platform, and began updating code and network security settings to strengthen defenses. Edge Imaging advised schools that, because individual affected individuals could not be identified, cooperation was needed to notify school communities about the incident and to support the yearbook rebuilding process. The updates were posted on Edge Imaging’s cyber‑incident webpage, which will remain available for six months before being deactivated if no further information emerges.
