Observed Signal · May 13, 2026 · Regulatory Inquiry · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
US Lawmakers Demand Answers from Instructure
U.S. House Homeland Security Committee members have asked Instructure to testify after the education‑software maker was breached twice, with hackers stealing personal data belonging to millions of students. Committee chair Representative Andrew Garbarino wrote to Instructure CEO Steve Daly seeking explanations about how threat actors repeatedly accessed Canvas systems, what data were taken, how affected schools were notified, and the company's coordination with CISA. Instructure confirmed it “reached an agreement” with the hackers and said the attackers provided evidence that stolen data were deleted; a representative of the ShinyHunters group told TechCrunch it would not continue extortion but declined to disclose ransom details. Lawmakers say the repeated intrusion raises questions about Instructure’s incident response and obligations to institutions and individuals whose data it stores.
A major education SaaS provider suffered repeat breaches exposing student data and is now subject to a congressional inquiry with CISA involvement — this raises systemic concerns about data security, incident response, and institutional trust that affect vendors and customers across sectors.
Track Instructure Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- The U.S. House Homeland Security Committee requested testimony from Instructure executives about two separate breaches of Canvas.
- Representative Andrew Garbarino, chair of the committee, sent a formal letter to Instructure CEO Steve Daly requesting answers and testimony.
- CISA (U.S. Cybersecurity and Infrastructure Security Agency) has been called in to assist with the incident.
- Instructure said it “reached an agreement” with the hackers and that the hackers provided evidence claiming the stolen data were deleted.
- The hacker group ShinyHunters reportedly claimed responsibility and said it would not continue extortion but did not disclose ransom amounts.
Connected Companies & Entities
1 Entity mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Hackers Deface Canvas Login Pages After Instructure Breach
On 2026-05-07, TechCrunch reported that the cybercrime group ShinyHunters claimed a second compromise of education‑technology provider Instructure, publishing an extortion message on the Canvas login pages of three separate schools. The attackers injected an HTML file that altered login screens and threatened to publish stolen student data on May 12 unless Instructure negotiated a settlement. The incident follows an earlier disclosed breach (reported May 5) in which attackers stole students’ names, personal emails and teacher‑student messages. Instructure spokesperson Brian Watkins said the company took Canvas offline, confirmed the actors exploited an issue related to Free‑For‑Teacher accounts, temporarily shut down those accounts, investigated, and then restored access to Canvas. ShinyHunters previously publicized stolen files on a leak site and claimed data affecting thousands of schools and millions of people.
Instructure Breach: ShinyHunters Steal Student Data
Instructure confirmed a data breach that exposed students' private information after the hacking gang ShinyHunters claimed responsibility. TechCrunch reviewed a sample of allegedly stolen records that included student and staff names, personal email addresses, messages between teachers and students, and some phone numbers from two U.S. schools (one in Massachusetts and one in Tennessee). The sample did not contain passwords. ShinyHunters posted a list of roughly 8,800 schools it says were affected and claimed the breach impacts about 275 million people; the group told TechCrunch the unique emails in the dataset number about 231 million. Instructure says it has more than 8,000 institutional customers and is publishing incident updates on its status site, and some products such as Canvas have been restored after maintenance.
House Democrats Demand AI CEOs Testify After Hacks
House Democrats led by Rep. Greg Casar asked House Speaker Mike Johnson to invite the CEOs of major AI companies, including OpenAI and Anthropic, to testify before Congress following a recent series of hacking incidents attributed to AI models. In a letter shared with CNBC, the lawmakers said the breaches raise serious safety and security concerns and urged executives to answer, under oath, about causes, company failures or negligence, and what regulation is needed. The move underscores growing congressional scrutiny of advanced AI systems amid calls for government oversight.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
