# Congress Demands Answers from Instructure Over Canvas Breach: ShinyHunters Strike Twice in One Week


Educational technology company Instructure faces intense congressional scrutiny after its Canvas learning management system fell victim to not one, but two separate cyberattacks from the ShinyHunters cybercrime gang within a single week—raising critical questions about the company's incident response capabilities and its ability to protect data from thousands of schools and universities.


## The Threat


The ShinyHunters cybercrime group has emerged as one of the most prolific and aggressive threat actors targeting enterprise SaaS platforms. In May 2026, the group demonstrated its capabilities with devastating precision by compromising Instructure's Canvas platform twice—first breaching the system on or before May 1, then returning for a second attack on May 7, just one day after Instructure declared the initial intrusion "fully resolved."


The attacks exposed sensitive personal information from more than 9,000 educational institutions, affecting students, faculty, and staff across the United States and globally. ShinyHunters claimed to have exfiltrated over 3 terabytes of data, including:


  • Student and staff names
  • Email addresses
  • Student ID numbers
  • Private messages and communications
  • Additional identifying information

  • The second breach proved particularly damaging to Instructure's reputation, as it occurred while the company was still investigating and remediating the first attack.


    ## Background and Context


    Canvas, owned by Instructure, serves as the primary learning management system for thousands of educational institutions worldwide. LMS platforms are critical infrastructure in modern education, hosting grades, coursework, communications, and sensitive student data. The platform's widespread adoption and centralized nature make it an attractive target for cybercriminals seeking maximum impact and data volume in a single attack.


    ShinyHunters has built a reputation as a sophisticated and persistent threat actor. The group operates primarily through extortion tactics, threatening to publicly release stolen data unless victims pay ransoms. Past targets include Fortune 500 companies and critical infrastructure providers. Their willingness to return to the same target within days of an initial breach suggests either:


    1. Exploitable vulnerabilities remained unfixed after the first attack

    2. Multiple distinct access points existed within Instructure's infrastructure

    3. Inadequate segmentation allowed rapid re-entry to compromised systems


    ## Timeline of Events


    | Date | Event |

    |------|-------|

    | May 1, 2026 | Initial breach disclosed; Instructure acknowledges threat actors obtained "certain identifying information of users" |

    | May 1-5, 2026 | Canvas taken offline for investigation; Instructure works to remediate |

    | May 6, 2026 | Instructure declares intrusion "resolved" and Canvas "fully operational" |

    | May 7, 2026 | ShinyHunters returns and compromises the system again |

    | May 15, 2026 | House Committee on Homeland Security demands briefing from Instructure CEO |

    | May 21, 2026 | Deadline for Instructure to appear before committee |


    Instructure's rapid pivot from declaring the breach "resolved" to experiencing a second intrusion within 24 hours suggests either incomplete vulnerability remediation or that attackers had established persistent access mechanisms during the first breach.


    ## Technical Details


    While full technical details remain under investigation, several factors likely contributed to the recurrence:


    Incomplete Vulnerability Patching: If the initial breach resulted from zero-day exploits or newly disclosed vulnerabilities, simply taking Canvas offline may not have addressed underlying code flaws. Instructure may have failed to patch all affected systems or versions.


    Lateral Movement and Persistence: Threat actors often establish multiple persistent access points during an initial compromise—backdoors, privileged accounts, or scheduled tasks that allow re-entry even after the initial vulnerability is closed. ShinyHunters may have leveraged these mechanisms on May 7.


    Inadequate Segmentation: If customer data, administrative systems, and backup infrastructure shared network segments without proper access controls, attackers may have pivoted from one system to another, making complete remediation difficult.


    Supply Chain or Third-Party Compromise: The timeline raises questions about whether a third-party service or API integration used by Canvas remained compromised, providing an alternate attack vector.


    ## Implications for the Education Sector


    The Canvas breaches represent a watershed moment for educational institutions relying on centralized SaaS platforms:


    Data Privacy Exposure: Students whose private messages were accessed face potential identity theft, social engineering, and privacy violations. The inclusion of student ID numbers and identifying information creates a complete profile for malicious actors.


    Service Continuity Risks: Taking Canvas offline disrupted grade reporting, assignment submission, and communication—critical functions during active semesters. Institutions must reconsider their dependence on single-vendor LMS solutions.


    Ransomware Precedent: If Instructure paid a ransom to ShinyHunters (a question Congress is now investigating), it sets a concerning precedent that educational technology vendors will capitulate to extortion, encouraging further attacks.


    Regulatory Exposure: Depending on the states and countries where affected students reside, FERPA (Family Educational Rights and Privacy Act), GDPR, and state privacy laws may mandate notifications and potential liability.


    Institutional Liability: Universities and K-12 districts may face legal action from students and families whose data was compromised while under Instructure's protection.


    ## Instructure's Response and Congressional Questions


    House Committee on Homeland Security Chairman Andrew R. Garbarino's letter to Instructure CEO Steve Daly raised several critical questions:


    1. Why was a second breach possible?

    The committee specifically questioned Instructure's "apparent failure to fully remediate the underlying vulnerabilities during that window" between breaches. This is the most damaging allegation—suggesting the company did not eliminate the root cause.


    2. Was a ransom paid?

    Executives and lawmakers want to know if Instructure negotiated with ShinyHunters, potentially funding the group's operations and setting a precedent for future extortion.


    3. Is there a connection to the Salesforce incident?

    The letter references a previous attack on Instructure's Salesforce environment in fall 2025, raising questions about whether systemic security deficiencies enabled multiple compromises.


    4. What is the full scope of exposed data?

    Instructure's initial disclosures may understate what was actually exfiltrated. The committee demanded clarification on whether the 3TB ShinyHunters claimed is accurate.


    Instructure stated it had reached an "agreement" with ShinyHunters the same day Congress sent its letter—language that typically indicates ransom negotiation in cybercrime circles, though the company has not explicitly confirmed payment.


    ## HackWire Analysis


    The Canvas incident exposes a critical vulnerability in how large software vendors respond to high-severity breaches: the illusion of swift remediation. Declaring a breach "fully resolved" within five days suggests either remarkable incident response capability or inadequate post-incident investigation. The immediate second breach confirms the latter.


    This pattern mirrors past major incidents. When SolarWinds was compromised in December 2020, the company's initial response similarly underestimated the breach scope and attacker persistence. The difference here is timing: Canvas operators saw their critical system restored, operations resumed, and then compromised again before security patches could be validated in production.


    The education sector presents a unique vulnerability profile. Unlike financial services or healthcare, which operate with mature incident response frameworks and regulatory oversight, educational institutions often lack dedicated security teams. They are captive audiences—there is no switching Canvas mid-semester. This creates perfect conditions for extortion: high impact, limited alternatives, and urgency.


    The congressional investigation will likely expose whether Instructure paid ransom, setting a dangerous precedent. If payment occurred, we can expect ShinyHunters and copycat groups to systematically target other education SaaS vendors—Canvas competitors like Blackboard, D2L, and Brightspace should assume they are now on accelerated target lists.


    For institutions still affected: demand Instructure provide forensic evidence that the second breach was contained, comprehensive vulnerability assessments from third-party auditors, and written guarantees against future incidents backed by breach insurance. Accept no timeline promises from the vendor—only completed, audited remediation.


    HackWire Editorial


    ## Recommendations


    For Educational Institutions:

  • Conduct immediate breach assessments with third-party forensic firms; do not rely solely on Instructure's internal findings
  • Review data backup integrity to ensure student records are clean and not contaminated by compromised versions
  • Implement multi-factor authentication (MFA) for all Canvas administrative accounts
  • Segment Canvas infrastructure from administrative and financial systems to contain future breaches
  • Document all notification and remediation steps for regulatory compliance and potential litigation
  • Evaluate alternative LMS vendors as part of long-term risk mitigation

  • For Instructure:

  • Publish a detailed post-mortem explaining both the initial vulnerability and why the second breach was possible
  • Engage independent third-party security assessments and publish results
  • Implement continuous vulnerability scanning and patch management workflows
  • Establish a vulnerability disclosure program to identify gaps before attackers do
  • Provide affected institutions with complimentary forensic support and identity protection services

  • For Regulators:

  • Establish minimum SLA requirements for SaaS breach notification (e.g., initial disclosure within 24 hours, complete investigation within 14 days)
  • Mandate third-party security certifications for education technology vendors handling FERPA-protected data
  • Investigate whether ransom was paid, and if so, consider enforcement action under anti-money-laundering statutes

  • ---


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)