Policy & Regulation
Instructure faces House probe over student data breaches
The U.S. House Homeland Security Committee is investigating Instructure following cyberattacks that compromised the personal data of millions of students worldwide.
The House Homeland Security Committee has launched an investigation into Instructure regarding its response to cyberattacks that exposed the personal data of millions of students worldwide. Representative Andrew Garbarino, the chair of the House Homeland Security Committee, is leading the inquiry into the hacks and data breach. The committee, which holds jurisdiction over government activities relating to homeland security, has demanded that the company provide detailed information about the security incidents. The Cybersecurity and Infrastructure Security Agency (CISA), the US cybersecurity agency, is assisting with the incident. Instructure is the developer of Canvas, a school information portal software.
U.S. House lawmakers are demanding information from Instructure regarding its response to cyberattacks and are seeking a closed-door briefing with Instructure leadership rather than public testimony. The briefing is intended to address the company’s incident response capabilities and its coordination with CISA. The committee wants chief executive Steve Daly or another senior executive to address how hackers repeatedly broke into the systems of Instructure, which develops the Canvas school information portal software, and to disclose the specific types of student data that were compromised during the breaches.
Committee chair Andrew Garbarino cited the company’s repeated breaches as evidence of systemic vulnerabilities. Garbarino stated that the second breach by the same hackers raises serious questions about the company’s incident response capabilities and its obligations to the institutions and individuals whose data it holds. In a letter to the company, Garbarino wrote: “The scale and timing of the Instructure breach, and the demonstrated inability of a major educational technology vendor to contain a threat actor following an initial intrusion, are precisely the kind of systemic vulnerabilities this Committee has a responsibility to examine,”
Meanwhile, Instructure, the twice-hacked education software maker, confirmed it reached an agreement with the ShinyHunters hackers, who claimed to have deleted the stolen data. The congressional investigation was originally publicized on May 13, and the committee’s request was updated on May 14 to clarify that lawmakers are seeking a closed-door briefing rather than public testimony from the company’s executives.
Why it matters
The investigation highlights growing congressional scrutiny over the incident response capabilities of major ed-tech vendors, particularly when repeated breaches expose the sensitive data of millions of users.