Cybersecurity Policy Report, Back-to-Back Ransomware Attacks on Ed Tech Firm Attract Congressional Scrutiny, (May 11, 2026)
Organizations Mentioned:Instructure Holdings, Inc. | Preformed Line Products Co.

The breach of a widely used virtual learning environment by a ransomware group has attracted the scrutiny of the House Homeland Security Committee.
Committee Chairman Andrew Garbarino (D., N.Y.) has requested a briefing by May 21 from Steve Daly, the chief executive officer of Instructure Holdings, Inc., provider of the Canvas learning management system.
“Within the span of one week, the cybercriminal group known as ShinyHunters breached Instructure twice,” Rep. Garbarino noted today in a letter to Mr. Daly.
“The group reportedly first struck on May 1, accessing personal data belonging to students and faculty across thousands of institutions, and struck again on May 7, defacing Canvas login pages nationwide and posting ransom demands directly on students’ screens,” Rep. Garbarino said.
“With students at more than 8,000 institutions navigating final examinations and end of semester deadlines, the disruption of a platform that Instructure itself describes as serving more than 30 million active users globally is a matter of national concern,” he said.
ShinyHunters claimed “to have accessed records belonging to approximately 275 million students, teachers, and other staff across nearly 9,000 institutions worldwide,” Rep. Garbarino observed. “Whether or not those figures are fully accurate, the gap between Instructure’s public characterization of this event and the scale suggested by the attacker’s own claims warrants a full and transparent accounting.”
On Instructure’s website, Mr. Daly apologized to customers for the breach and the company’s response. “You deserved more consistent communication from us, and we didn't deliver it. I'm sorry for that,” he said in a statement.
“Last week, we made a call to get the facts right before speaking publicly. That instinct isn't wrong, but we got the balance wrong. We focused on fact-finding and went quiet when you needed consistent updates. You've been clear about that, and it's fair feedback. We will change that moving forward,” Mr. Daly told customers.
The hackers breached Canvas by exploiting a vulnerability in its “Free for Teacher environment,” Mr. Daly explained. “We temporarily disabled Free for Teacher while we complete a full security review. We know that's disruptive, and we didn't make that call lightly. But keeping the entire Canvas platform secure has to come first.”
Data accessed by the hackers included user names, e-mail addresses, course names, enrollment information, and messages, he said. Instructure has enlisted CrowdStrike Holdings, Inc., to investigate the breach and also notified the Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency, he added.
Rep. Garbarino, however, said the back-to-back breaches on raised questions that the Homeland Security Committee would like answered.
“The recurrence of an intrusion within days of an initial breach disclosure, and Instructure’s apparent failure to fully remediate the underlying vulnerabilities during that window, raise serious questions about the company’s incident response capabilities and its obligations to the institutions and individuals whose data it holds,” he said.
“The Committee has broad jurisdiction over cybersecurity threats to the United States,” he added. “The scale and timing of the Instructure breach, and the demonstrated inability of a major educational technology vendor to contain a threat actor following an initial intrusion, are precisely the kind of systemic vulnerabilities this Committee has a responsibility to examine.”
MainStory: TopStory FederalLegislation DataSecurity DataBreach