Observed Signal · May 13, 2026 · Regulatory Inquiry · Source: techcrunch · Impact: 3/5 · Sentiment: Negative

US Lawmakers Demand Answers from Instructure

Executive Signal Summary

U.S. House Homeland Security Committee members have asked Instructure to testify after the education‑software maker was breached twice, with hackers stealing personal data belonging to millions of students. Committee chair Representative Andrew Garbarino wrote to Instructure CEO Steve Daly seeking explanations about how threat actors repeatedly accessed Canvas systems, what data were taken, how affected schools were notified, and the company's coordination with CISA. Instructure confirmed it “reached an agreement” with the hackers and said the attackers provided evidence that stolen data were deleted; a representative of the ShinyHunters group told TechCrunch it would not continue extortion but declined to disclose ransom details. Lawmakers say the repeated intrusion raises questions about Instructure’s incident response and obligations to institutions and individuals whose data it stores.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A major education SaaS provider suffered repeat breaches exposing student data and is now subject to a congressional inquiry with CISA involvement — this raises systemic concerns about data security, incident response, and institutional trust that affect vendors and customers across sectors.

SIGNAL RADAR

Track Instructure Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • The U.S. House Homeland Security Committee requested testimony from Instructure executives about two separate breaches of Canvas.
  • Representative Andrew Garbarino, chair of the committee, sent a formal letter to Instructure CEO Steve Daly requesting answers and testimony.
  • CISA (U.S. Cybersecurity and Infrastructure Security Agency) has been called in to assist with the incident.
  • Instructure said it “reached an agreement” with the hackers and that the hackers provided evidence claiming the stolen data were deleted.
  • The hacker group ShinyHunters reportedly claimed responsibility and said it would not continue extortion but did not disclose ransom amounts.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: May 13, 2026
Original Coverage Title: “US lawmakers demand answers from Instructure after Canvas data breaches”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Security / Data BreachMay 7, 2026

Hackers Deface Canvas Login Pages After Instructure Breach

On 2026-05-07, TechCrunch reported that the cybercrime group ShinyHunters claimed a second compromise of education‑technology provider Instructure, publishing an extortion message on the Canvas login pages of three separate schools. The attackers injected an HTML file that altered login screens and threatened to publish stolen student data on May 12 unless Instructure negotiated a settlement. The incident follows an earlier disclosed breach (reported May 5) in which attackers stole students’ names, personal emails and teacher‑student messages. Instructure spokesperson Brian Watkins said the company took Canvas offline, confirmed the actors exploited an issue related to Free‑For‑Teacher accounts, temporarily shut down those accounts, investigated, and then restored access to Canvas. ShinyHunters previously publicized stolen files on a leak site and claimed data affecting thousands of schools and millions of people.

Read assessment
Data breachMay 5, 2026

Instructure Breach: ShinyHunters Steal Student Data

Instructure confirmed a data breach that exposed students' private information after the hacking gang ShinyHunters claimed responsibility. TechCrunch reviewed a sample of allegedly stolen records that included student and staff names, personal email addresses, messages between teachers and students, and some phone numbers from two U.S. schools (one in Massachusetts and one in Tennessee). The sample did not contain passwords. ShinyHunters posted a list of roughly 8,800 schools it says were affected and claimed the breach impacts about 275 million people; the group told TechCrunch the unique emails in the dataset number about 231 million. Instructure says it has more than 8,000 institutional customers and is publishing incident updates on its status site, and some products such as Canvas have been restored after maintenance.

Read assessment
RegulationAug 10, 2026

House Democrats Demand AI CEOs Testify After Hacks

House Democrats led by Rep. Greg Casar asked House Speaker Mike Johnson to invite the CEOs of major AI companies, including OpenAI and Anthropic, to testify before Congress following a recent series of hacking incidents attributed to AI models. In a letter shared with CNBC, the lawmakers said the breaches raise serious safety and security concerns and urged executives to answer, under oath, about causes, company failures or negligence, and what regulation is needed. The move underscores growing congressional scrutiny of advanced AI systems amid calls for government oversight.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.