# Congressional Pressure Mounts as House Demands Instructure Testimony on Dual Canvas Cyberattacks


The U.S. House Committee on Homeland Security has formally called for testimony from Instructure executives regarding two devastating cyberattacks by the ShinyHunters extortion group that compromised Canvas, a learning management platform serving tens of millions of students, educators, and administrators across North America. The dual breaches—occurring within just one week—have triggered a high-level federal investigation and raised critical questions about the company's security practices and incident response capabilities.


## The Attacks: A One-Week Campaign of Escalating Disruption


On May 3, 2026, Instructure disclosed that it had discovered a significant security breach affecting its Canvas platform. The company confirmed that threat actors had first compromised its systems on April 29, beginning what would become a two-phase assault on one of the education sector's most critical digital infrastructures.


The First Breach: Massive Data Theft


In the initial intrusion, ShinyHunters gained access to Instructure's networks and exfiltrated an enormous volume of student and staff data. According to the threat actors' own claims, they stole 280 million data records from across 8,809 educational institutions—including colleges, school districts, and online education platforms. The exposed information included:


  • Student and staff names
  • Email addresses
  • Student identification numbers
  • Private messages exchanged between students and teachers on the Canvas platform

  • Importantly, Instructure clarified that the breach did not expose passwords, financial information, or government-issued identification numbers—a partial relief for affected institutions, though the exposure of educational records and private communications remains serious.


    The Second Attack: Portal Defacement and Extortion


    The situation escalated dramatically when ShinyHunters launched a second offensive, this time targeting the user-facing Canvas login portals at schools and universities nationwide. Rather than remaining hidden, the threat actors used cross-site scripting (XSS) vulnerabilities to obtain authenticated administrator sessions, allowing them to modify login pages and inject extortion demands directly into the platforms students and teachers rely on daily.


    This attack struck at a particularly damaging moment: during final exams and end-of-semester activities. The disruption affected institutions across 11 states—California, Florida, Georgia, Oklahoma, Oregon, Nevada, North Carolina, Tennessee, Utah, Virginia, and Wisconsin—with some colleges forced to cancel examinations altogether, leaving students, faculty, and administrators scrambling to reschedule critical academic assessments.


    ## Technical Details: XSS as an Attack Vector


    The second attack's use of cross-site scripting (XSS) vulnerabilities deserves particular scrutiny. XSS flaws are among the most well-documented and preventable classes of web vulnerabilities, yet they remain an effective entry point for attackers at scale.


    By exploiting XSS weaknesses, ShinyHunters were able to:


    1. Steal authenticated admin sessions by injecting malicious scripts into Canvas pages

    2. Gain administrative control over login portals across multiple institutions

    3. Inject extortion messages that appeared to come from Canvas itself, adding credibility to ransom demands

    4. Maintain persistence long enough to disrupt operations during critical academic periods


    The fact that such a preventable vulnerability class enabled this level of disruption suggests potential gaps in Instructure's application security testing, code review practices, and web application firewall configurations.


    ## Congressional Investigation and Ransom Implications


    On May 12, House Committee on Homeland Security Chairman Andrew R. Garbarino formally requested that Instructure CEO Steve Daly provide testimony about both incidents by May 21, 2026. The committee's letter states the investigation is examining:


  • The circumstances and timeline of both breaches
  • The extent of data compromised
  • Instructure's containment and notification procedures
  • The company's obligations to protect sensitive educational data

  • The committee's concerns extend beyond the technical breaches themselves. The letter references "serious questions" about Instructure's incident response capabilities—a pointed critique given that the company experienced two separate compromises within seven days.


    The Ransom Question


    Perhaps most significantly, Instructure disclosed on May 12 that it had reached an agreement with ShinyHunters to halt the public leak and ensure stolen data was deleted. The company did not explicitly confirm whether payment was involved, but cybersecurity industry analysts note that extortion groups rarely cease operations and agree to data deletion without receiving negotiated compensation.


    If Instructure did pay a ransom, it would represent a calculated decision to negotiate with the threat group rather than maintain a "no ransom" stance. Such decisions carry implications beyond the immediate incident—they may signal to other threat actors that a major technology provider serving the education sector is willing to pay, potentially attracting future attacks.


    ## Scope and Impact: 8,809 Institutions at Risk


    The breadth of this incident cannot be overstated. Canvas is one of the world's largest learning management platforms, with integration across community colleges, universities, K-12 districts, and corporate training programs. The exposure of data from 8,809 institutions means the breach touches educational ecosystems serving millions of students.


    For affected organizations, the incident creates both immediate and long-term concerns:


    | Concern | Impact |

    |---------|--------|

    | Academic Disruption | Exam cancellations and rescheduling during critical periods |

    | Student Privacy | Personal messages and identifying information exposed to criminals |

    | Institutional Liability | Potential FERPA violations and regulatory exposure |

    | Community Trust | Erosion of confidence in digital learning infrastructure |

    | Ongoing Threat | Exposed student records available on criminal markets |


    ## Background: ShinyHunters' Track Record


    ShinyHunters has established itself as a prolific extortion operation, frequently targeting large organizations across multiple sectors. The group's willingness to conduct secondary attacks—adding public disruption to data theft—represents an escalation in extortion tactics. Rather than simply threatening to leak data, they publicly defaced Canvas portals, guaranteeing media coverage and institutional panic during vulnerable periods.


    This tactic of public disruption paired with data theft has proven effective at pressuring organizations into negotiation, as the reputational and operational damage occurs in real time.


    ## Implications for Educational Technology Security


    This incident exposes critical vulnerabilities in how educational institutions approach security for third-party platforms:


    1. Shared Infrastructure Risk: When a single platform serves thousands of institutions, a single compromise affects an entire ecosystem

    2. Incident Response Lag: The gap between breach detection (April 29) and public disclosure (May 3) allowed attackers to conduct a second offensive

    3. Preventable Vulnerabilities: XSS exploitation suggests gaps in fundamental application security practices

    4. Ransom Dynamics: Corporate willingness to pay may incentivize similar attacks on other education providers


    ---


    ## HackWire Analysis


    This incident reveals a troubling pattern: major education technology providers are increasingly attractive targets for extortion groups, yet institutions have limited visibility into third-party security practices. Canvas serves millions of students globally, yet most of those institutions had no advance warning of the April 29 compromise until days later—by which time the threat actors had already conducted a second, more disruptive attack.


    What distinguishes this breach from typical data exfiltration is the tactical escalation: ShinyHunters didn't simply threaten to leak data and wait for negotiation. They actively disrupted operations during final exams—a period guaranteed to maximize institutional pressure and public attention. The defacement of login portals transformed an invisible breach into a visible crisis that made headlines and triggered congressional attention.


    The congressional investigation is noteworthy because it signals that federal lawmakers now view education technology security as a critical infrastructure concern. This is appropriate: Canvas serves millions of K-12 and higher education students, and disruptions during academic assessment periods have measurable impact on educational outcomes.


    For defenders, this incident underscores why organizations cannot rely solely on vendors' security assurances. Institutions using Canvas should conduct independent audits of their data access controls, implement additional monitoring for suspicious administrative activity, and establish incident response protocols for when vendors experience breaches. Additionally, the apparent use of basic XSS vulnerabilities to conduct the second attack suggests that fundamental application security practices—input validation, output encoding, content security policies—remain inadequately implemented even at major providers.


    The ransom agreement also matters. If Instructure paid, it sends a signal to threat actors that education technology companies will negotiate. If future incidents follow, institutions should expect similar pressure tactics and prepare accordingly. — HackWire Editorial


    ---


    ## Recommendations for Affected Organizations


    Educational institutions relying on Canvas should prioritize the following actions:


    1. Audit Student Data Access: Review which student records were exposed and monitor credit reporting agencies for fraudulent activity on behalf of affected minors

    2. Strengthen Administrative Controls: Implement multi-factor authentication for all administrative Canvas accounts and monitor login anomalies

    3. Review Vendor Security Requirements: Establish contractual security benchmarks and audit rights for critical third-party platforms

    4. Develop Incident Response Plans: Prepare communication strategies and academic continuity procedures for future vendor compromises

    5. Monitor Threat Intelligence: Track if student data appears on underground forums or criminal marketplaces


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)