New Harris Poll data shows 84% of California workers are interested in upskilling as demand grows for clearer, more portable credentials
, /PRNewswire/ -- Instructure, the leading learning technology ecosystem and maker of Canvas Learning Management System (LMS) and Parchment digital credentials, today released new research examining learning, skills and workforce readiness across California. The findings show strong demand for skills development alongside widespread confusion around credentials, making it harder for workers to translate learning into potential economic mobility at a time when employers are increasingly hiring for skills and workers are navigating more frequent career changes. This disconnect also makes it more difficult for employers to identify qualified talent and align hiring with evolving skill needs.
Among the findings:
84% of workers are interested in upskilling 75% say their work is skills-based 69% say they feel unprepared to succeed in today's workforce 47% say they are unsure which credentials employers value 78% say transferring credentials between institutions is more difficult than it should be 90% say standardized credentials could unlock greater mobility across education and workforce systems The study, conducted by The Harris Poll on behalf of Instructure, surveyed more than 500 adults across California who are working or seeking work. As one of the largest and most dynamic labor markets in the country, California serves as a leading indicator of how skills-based pathways are reshaping education and employment, alongside statewide efforts like the Career Passport to create more portable, skills-based records.
The findings reflect a workforce that is actively building new skills while navigating uncertainty about how to apply them. At the same time, the research highlights challenges in how workers understand and use credentials to advance across education and employment.
Credentials, including certificates, certifications and digital records of learning, are designed to help individuals demonstrate skills to employers and move more easily between education and work. When credentials are difficult to interpret or transfer, they can create friction for both workers and employers trying to identify and validate skills.
"California workers are ready to build relevant skills and move into new opportunities, but the systems around them haven't fully caught up," said Melissa Loble, chief academic officer at Instructure. "When 90% of workers say credentials need to be clearer and more consistent, that's a strong signal there's an opportunity to make it easier for people to turn learning into real economic mobility."
With broad support for clearer and more standardized credentials, the findings point to an opportunity to reduce friction in how skills are understood, shared and valued across education and employment. The survey results offer a state-level view into how Californians are navigating learning and work as skills-based paths continue to expand.
The full report is available at Instructure.com.
Survey Method
This survey was conducted online within the United States by The Harris Poll on behalf of Instructure from February 9 - 18, 2026, among 507 adults ages 18 and older who reside in California and are employed full-time, part-time, or self-employed, or looking for work. The sampling precision of Harris online polls is measured by using a Bayesian credible interval. For this study, the sample data is accurate to within +/- 5.8 percentage points using a 95% confidence level. This credible interval will be wider among subsets of the surveyed population of interest. For complete survey methodology, including weighting variables and subgroup sample sizes, please contact Brian Watkins at [email protected].
About Instructure
Instructure is shaping the future of learning by delivering a future-ready ecosystem that helps learners thrive in tomorrow's landscape. Our vision is to drive a future where education technology seamlessly amplifies human potential, empowering people to excel in a perpetually changing world. The Instructure ecosystem supports educators, institutions, and learners across K-12, higher education, and the workforce—enhancing experiences at every age, every stage, and every pivotal transition. Discover more at Instructure.com
Contact
Brian Watkins
Corporate Communications
Instructure
(801) 658-7525
New tiered structure expands access to advanced AI-supported capabilities and ongoing enhancements to the Canvas experience SALT LAKE CITY, April 21, 2026 /PRNewswire/ -- I nstructure, the leading learning ecosystem and maker of Canvas LMS, today announced a comprehensive set of updates at "New & Next Showcase," headlined by the introduction of a new, simplified tiered structure for Canvas designed to make it easier for institutions, districts and organizations to access expanded capabilities across the Instructure ecosystem. As institutions navigate increasing complexity across tools, workflows and emerging technologies, Instructure is evolving the way Canvas delivers value.
Collaboration will explore how a new generation of learners is reshaping workforce development and what organizations must do to keep pace
, /PRNewswire/ -- Instructure, the leading learning technology ecosystem and maker of Canvas Learning Management System (LMS) and Canvas Career, today announced it has been named an Eminence Partner by Brandon Hall Group, a leading independent Human Capital Management (HCM) research and analyst firm. The partnership focuses on advancing independent research and executive dialogue on the future of work, the growing importance of lifelong learning and the critical role of workforce learning in connecting education to employment.
A New Era of Learning: From Education to Employment and Beyond
As organizations face accelerating change in skills and talent needs, learning is no longer confined to a single phase of life. The half-life of many skills continues to shrink, with some estimates suggesting critical skills can become outdated in just a few years, placing new pressure on organizations to continuously reskill and upskill their workforce. Instructure is collaborating with Brandon Hall Group to examine how a new generation of learners engages with continuous, flexible and career-connected learning experiences that extend beyond traditional academic pathways.
This shift is redefining how organizations approach capability building, employee development and long-term workforce resilience. Instructure brings a distinct perspective to this work, informed by its role supporting millions of learners across K-12, higher education and the workforce. This cross-lifecycle view provides insight into how learning behaviors evolve as individuals move from structured academic environments to more self-directed, skills-based learning throughout their lifetime.
Advancing Research on Workforce Learning and Skills Development
As part of the collaboration, Instructure and Brandon Hall Group will co-develop a Bellwether Research Report examining emerging trends and challenges in how organizations build and sustain workforce capability. The research will explore changing learner expectations, the rise of lifelong learning and the need for organizations to better align learning experiences with measurable, real-world outcomes.
The findings are designed to support learning and development leaders, HR executives and business decision-makers as they adapt workforce strategies to a rapidly changing landscape. Insights from the research aims to help organizations identify gaps in current learning approaches, better align training with business priorities and design more effective, future-ready workforce learning strategies.
"At Brandon Hall Group, our mission is to provide evidence-based insights that help organizations make better decisions about their people and performance," said Michael Rochelle, chief strategy officer and principal analyst at Brandon Hall Group. "This partnership with Instructure enables us to deepen our research into how organizations can align learning with business impact, while addressing the growing need for continuous, career-connected development."
Brandon Hall Group has recognized Instructure as a Smartchoice® Preferred Provider, citing the company's ability to deliver credible, high-impact solutions that drive measurable outcomes for organizations.
"Learning extends beyond graduation and continues throughout a person's life," said Melissa Loble, chief learning officer at Instructure. "As today's learners expect continuous development throughout their careers, organizations must rethink how they support skills-driven learning at every stage. Through this partnership, we are contributing research and insight to help define what effective lifelong learning looks like in practice."
Partnership Recognition and Industry Collaboration
As an Eminence Partner, Instructure joins a select group of organizations collaborating with Brandon Hall Group to advance research and industry dialogue in learning and talent development. In addition to this designation, Instructure has been recognized as a Smartchoice Preferred Provider, reflecting independent validation of its ability to deliver impactful learning solutions that drive measurable outcomes.
This collaboration reflects Instructure's broader commitment to shaping the future of learning by contributing research and insight that helps organizations navigate the evolving relationship between education, skills development and work.
About Instructure
Instructure is shaping the future of learning by delivering a future-ready ecosystem that helps learners thrive in tomorrow's landscape. Our vision is to drive a future where education technology seamlessly amplifies human potential, empowering people to excel in a perpetually changing world. The Instructure ecosystem supports educators, institutions, and learners across K-12, higher education, and the workforce—enhancing experiences at every age, every stage, and every pivotal transition. Discover more at Instructure.com
About Brandon Hall Group™
Brandon Hall Group is the only professional development company that offers data, research, insights, and certification to Learning and Talent executives and organizations. The best minds in Human Capital Management (HCM) choose Brandon Hall Group to help them create future-proof employee development strategies for the new era of work.
For over 30 years, Brandon Hall Group has empowered, recognized, and certified excellence in organizations around the world, influencing the development of more than 10 million employees and executives. Its HCM Excellence Awards® are widely regarded as the "Academy Awards of Human Capital Management."
Brandon Hall Group's cloud-based platform delivers evidence-based insights across Learning and Development, Talent Management, Leadership Development, Diversity, Equity & Inclusion, Talent Acquisition, and HR/Workforce Management.
Learn more at www.brandonhall.com
Contact
Brian Watkins
Corporate Communications
Instructure
(801) 658-7525
Exclusive agreement accelerates Canvas migration support as institutions move away from legacy LMS solutions to Instructure's connected learning ecosystem
, /PRNewswire/ -- Instructure, the leading learning ecosystem and maker of Canvas LMS, today announced an exclusive strategic partnership with K16 Solutions, the leader in higher-ed automated data management. The partnership is focused on migration services for institutions moving from legacy LMS solutions to Canvas. Through the agreement, Instructure has secured exclusive access to K16's LMS migration services, further strengthening support for organizations transitioning to Canvas LMS as they modernize their digital learning infrastructure.
As institutions rethink the systems that support teaching and learning, many are moving beyond incremental improvements made by legacy LMS solutions and making structural transitions to meet the needs of the new learner. This partnership reflects growing market momentum toward Canvas and reinforces Instructure's commitment to helping institutions transition to a more flexible ecosystem with greater speed, confidence and continuity. By automating complex migration work and preserving critical course structure, assessments and content integrity, the partnership helps institutions move to Canvas with greater confidence. The agreement reduces one of the biggest barriers to changing LMS solutions: the risk and disruption of a traditional migration. With the assistance of K16, moving to Canvas means customers can focus more of their time on improving learning outcomes rather than managing transition tasks.
Institutions and organizations are moving beyond legacy LMS solutions and choosing platforms that can better meet the needs of the new learner," said Kevin Martin, vice president of sector strategy at Instructure. "Switching platforms can be complex and disruptive, especially when institutions need to protect content integrity, maintain continuity, and keep teaching and learning moving forward. Our exclusive partnership with K16 Solutions gives customers a clear path to Canvas — protecting critical course content while moving forward with confidence and speed."
The partnership comes as Instructure continues to see strong momentum from institutions seeking a modern learning ecosystem rather than a standalone point solution. Across K-12, higher education and workforce learning, institutions are focused on creating a more connected learning ecosystem that supports better outcomes, greater continuity and long-term innovation. Canvas serves as a flexible foundation that connects learning, assessment, analytics, credentials and partner technologies across the full learner journey.
"K16 Solutions is proud to expand our exclusive relationship with Instructure through this strategic partnership," said Sam Yaghoubi, SVP of Partnerships, K16 Solutions. "As institutions move away from competitive LMS solutions, they need a migration approach that protects content integrity, minimizes disruption and supports both immediate transition needs and long-term strategic goals. We see that momentum firsthand, as most of the institutions we support in LMS migrations are choosing Canvas as their next learning platform. Together with Instructure, we are helping institutions transition to Canvas with the expertise, continuity and confidence they need."
Canvas serves as the foundation of a modern learning ecosystem, enabling institutions to connect tools, integrate emerging technologies and support evolving teaching and learning needs. With this partnership, Instructure is strengthening its learning ecosystem by making it easier for institutions to transition to Canvas with confidence and continuity. To learn more about how this partnership simplifies LMS transitions to Canvas, visit k16solutions.com/solutions/lms-migration.
About K16 Solutions
K16 Solutions is transforming how institutions manage and maximize their data. Leveraging patented technology within its cloud-native Scaffold Platform, K16 delivers innovative solutions for data warehouse automation, migration, and archiving. Institutions across the globe trust K16 Solutions to reduce time, cost, and complexity while unlocking the full strategic value of their data. Learn more at k16solutions.com.
About Instructure
Instructure is shaping the future of learning by delivering a future-ready ecosystem that helps learners thrive in tomorrow's landscape. Our vision is to drive a future where education technology seamlessly amplifies human potential, empowering people to excel in a perpetually changing world. Instructure is setting potential in motion by connecting educators, institutions and learners across K–12, higher education and the workforce — enhancing experiences at every age, every stage and every pivotal transition. Discover more at Instructure.com.
CONTACT
Brian Watkins
Corporate Communications
Instructure
(801) 658-7525
Education tech giant Instructure has confirmed a data breach affecting students’ private information. The hacking and extortion gang ShinyHunters claimed responsibility for the breach.
The hackers claim to have stolen students’ names, their personal email addresses, and messages sent between teachers and students — the same type of data Instructure admitted was stolen.
Instructure is the latest corporate giant hacked by the ShinyHunters gang. The cybercriminals have targeted universities and cloud database companies in recent months, in efforts to steal vast amounts of people’s personal information and threaten to post the data online if the companies do not pay the hackers’ ransom.
A member of ShinyHunters shared a sample of the stolen data with TechCrunch, which included data from two schools in the United States, one in Massachusetts and one in Tennessee. In the case of the one in Massachusetts, the data included messages, which contain names, email addresses, and some phone numbers. As for the school in Tennessee, the sample included students’ full names and email addresses.
The sample did not contain passwords or the other types of data that Instructure said was unaffected by the breach.
TechCrunch is not naming the schools as they are not confirmed victims. Based on information that appears on their websites, both schools appear to use Instructure’s platform Canvas, which allows customers to manage coursework and assignments, and communicate with students.
ShinyHunters also shared a list of about 8,800 schools allegedly affected by the breach. TechCrunch could not confirm whether all the listed institutions were affected, nor whether they are Instructure customers. On its official site, Instructure says it has more than 8,000 institutions as customers.
When reached by TechCrunch, Instructure’s spokesperson Kate Holmes did not answer several questions about the incident, and instead referred to the company’s official page where it is publishing updates on the breach.
On its data leak site, where ShinyHunters claims responsibility for data breaches and attempts to pressure victims into paying a ransom, the hackers claim the breach affected close to 9,000 schools around the world, and 275 million people’s data, including students, teachers, and other staff. In an online chat, the ShinyHunters member told TechCrunch that the total unique emails included in the stolen data amount to 231 million.
Financially motivated hacking groups are known to exaggerate their claims to gather the attention of the media, as well as their victims.
As of Tuesday, Instructure said some of its products, such as Canvas, were restored for customers after undergoing maintenance.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.
You can contact or verify outreach from Lorenzo by emailing [email protected], via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.
On Tuesday, education tech giant Instructure disclosed a data breach where hackers stole students’ private information, including their names, personal email addresses, and messages sent between teachers and students.
Now, it appears hackers were able to compromise Instructure again — this time defacing several schools’ login pages to the company’s platform Canvas, which allows schools to manage coursework and assignments and communicate with students.
TechCrunch saw a message published by the cybercrime group ShinyHunters on the Canvas login pages of three separate schools. A review of the defaced portals shows that the hackers injected an HTML file that altered the login screens to display their message.
The message says the hackers will publish the stolen data on May 12 if the company does not “negotiate a settlement.”
At the time of writing, Instructure’s website appeared to be partially online, at times returning a “too many requests” error. The company’s Canvas portal displayed a notice saying it was “currently undergoing scheduled maintenance.”
Contact Us Do you have more information about this breach against Instructure? Or other data breaches? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.
Instructure spokesperson Brian Watkins told TechCrunch that when the company discovered that hackers had changed some customers’ login pages to its platform Canvas, “out of an abundance of caution, we immediately took Canvas offline to contain access and further investigate.”
“We have confirmed that the unauthorized actor exploited an issue related to our Free-For-Teacher accounts. As a result, we have made the difficult decision to temporarily shut down our Free-For-Teacher accounts,” said Watkins, who also said that the hackers who defaced the login pages are the same ones involved in the previous breach. “This gives us the confidence to restore access to Canvas, which is now fully back online and available for use.”
ShinyHunters had previously claimed responsibility for the original hack, publicizing it on its leak site — a website hackers use to publish stolen data and pressure victims into paying ransoms — in an effort to extort Instructure into paying to keep the data from going public. This apparent new hack, along with the fact that hackers chose to notify TechCrunch about the defaced login pages, indicate that the hackers are trying to ramp up pressure on Instructure and its customers, hoping to force them to cave to the hackers’ demands.
It’s unclear how the hackers were able to compromise the login pages. When asked, a member of ShinyHunters told TechCrunch that they couldn’t comment on specifics, but said this is a second, separate breach.
Following the original breach at Instructure, the hackers claimed to have stolen data from almost 9,000 schools around the world, with the stolen files allegedly containing information on 231 million people.
The group has compromised countless victims over the last couple of years, following the same financially motivated playbook: hack, publicize, and extort.
This story was updated to include comments from Instructure’s spokesperson.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.
You can contact or verify outreach from Lorenzo by emailing [email protected], via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at [email protected].
Instructure, which provides Canvas software to thousands of schools and universities around the world, did not say what it had given the hackers in exchange for the stolen data.
Instructure, the maker of the popular school information portal Canvas, said on Tuesday it has “reached an agreement” with the hackers who breached its systems twice, stole a huge amount of student and staff data, and disrupted thousands of schools that rely on the company’s software.
ShinyHunters, a financially motivated cybercrime group, took credit for the April 29 data breach, claiming to have stolen student and staff data, including personal information, of 275 million people. The hackers said they had compromised Canvas, which nearly 9,000 schools use to manage their students’ data and coursework.
The hackers last week breached the company for a second time, defacing the Canvas login pages on school websites, as part of efforts to pressure the company into paying their ransom.
Instructure said on its incident page late on Monday that as part of the agreement, the hackers had provided evidence that the stolen data was destroyed and that Canvas customers would not be extorted.
The company acknowledged that there is “never complete certainty” when negotiating with cybercriminals but noted that customers should not have to engage with the hackers.
Financial terms of the agreement were not disclosed, and Instructure did not say how much it paid the hackers. Instructure spokesperson Brian Watkins would not comment beyond the company’s statement or answer questions about the agreement when contacted on Tuesday.
In a post on its leak site, which TechCrunch has seen, ShinyHunters was threatening to publish the data it stole from Instructure if the company did not pay their extortion demand.
As of Tuesday, the listing had been removed from the ShinyHunters’ page, indicating that a ransom may have been paid.
A representative from ShinyHunters told TechCrunch: “The data is deleted, gone. The company and it’s [sic] customers will not further be targeted or contacted for payment by us.”
It’s not clear why Instructure paid the hackers. Governments, including the United States, have long urged victims of cybercrime not to pay ransoms to hackers, as this helps cybercriminals profit from their attacks. Security researchers have argued that victims cannot trust the word of malicious hackers — some cybercriminals have been found holding on to stolen data despite saying they had deleted it so they could continue extorting their victims.
The hack on Instructure mirrors a cyberattack on PowerSchool, which was hit by a massive data breach affecting 70 million students and staff in 2024. PowerSchool, which also makes school information software, paid the hackers to return the stolen data, but several of its customers were later extorted by another crime group that showed data from the breach that had not been destroyed.
The FBI said in a statement last week that it was “aware” of the system disruption affecting schools and educational institutions around the United States. The notice did not name Canvas, but it did mention that victims should “not send payment or respond” to the demands of cybercriminals.
The data stolen from Instructure, some of which TechCrunch has seen, includes students’ names, their personal email addresses, and messages exchanged by teachers and students, including private and personal information.
On its website, Instructure acknowledged that hackers had breached the company’s systems twice in under a year, but said that the two breaches were “distinct events” that involved different systems.
Instructure said it was still investigating the breach and validating its findings.
It’s not clear who at Instructure oversees or is responsible for cybersecurity, if not the company’s chief executive, Steve Daly. When contacted by TechCrunch, Instructure would not say if Daly plans to resign following the data breaches.
Are you a Canvas administrator or school notified about the breach? Have you received an extortion demand from the hackers? We want to hear from you. To contact this reporter securely, reach out via Signal username zackwhittaker.1337.
Updated with response from Instructure.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at [email protected].
The US House of Representatives is demanding testimony from representatives of Instructure, the twice-hacked company that owns the education platform Canvas. Lawmakers are seeking answers to explain the company's delayed response to cyberattacks that enabled bad actors to scrape the personal information of millions of students and teachers nationwide.
Instructure revealed this week that it had reached a deal with the hacker group ShinyHunters, under which the hackers would destroy copies of user data and agree not to extort users. ShinyHunters had hacked the platform first in April and again last week, and claimed to have targeted thousands of universities and school districts.
The House Homeland Security Committee said it is investigating the hack alongside the Cybersecurity and Infrastructure Security Agency. CISA has been working with Instructure as one of the "outside forensics experts" the company refers to in its incident FAQs, helping to "contain the activity, investigate and apply additional safeguards."
Now the House committee's chair, Rep. Andrew Garbarino, is examining whether Instructure's coordination with CISA was adequate in this situation. In a letter sent to Instructure CEO Steve Daly, Garbarino, a New York Republican, demanded to know how the company was hacked more than once. The House committee also wants more specific information about the types of sensitive information stolen during the hack.
Instructure said the personal data stolen during the Canvas hack included "information like usernames, email addresses, course names, enrollment information and messages."
The agreement with ShinyHunters called for the hackers to delete the data. Instructure said "there is never complete certainty when dealing with cybercriminals," but that it received digital confirmation, in the form of shred logs, that the stolen data had been deleted.
Instructure cautioned affected Canvas users against individual attempts to contact or bargain with the ShinyHunters group, saying its agreement "covers all impacted Instructure customers."
The hacker group first infiltrated Canvas systems on April 29, using a security flaw tied to Free-For-Teacher accounts. This allowed ShinyHunters to scrape personal information tied to students and educators.
While we don't know exactly how many institutions were affected, the hackers claimed they had targeted more than 9,000 universities and public school districts. Canvas is used in K-12 schools, so it's likely that the breach exposed sensitive information of underage students.
The situation escalated when the hackers cracked Instructure's security for a second time on May 7, leaving a message exposing their illicit activity to anyone attempting to sign in to Canvas. Instructure promptly moved Canvas into maintenance mode, during which students were unable to access the service.
If the ShinyHunters name sounds familiar, it's because it's a well-established collective of ransomware hackers. ShinyHunters is the same team that breached Anodot and absconded with some of Rockstar Games' business data in April.
Its previous targets largely consist of large tech companies like Microsoft, Cisco and AT&T, but the hackers have also ransomed information from insurance companies, credit unions and other institutions that handle sensitive data.
Canvas is currently operational, although the Free-For-Teacher accounts have been temporarily disabled as Instructure continues to investigate the exploit used to breach its systems.
Instructure asked customers to continue monitoring their accounts, though its external forensic partner has "found no evidence that the threat actor currently has access to the platform."
Instructure is organizing a webinar for its customers in order to "detail information about the cyberattack and [Instructure's] activities to harden the system." It's currently unclear when these will take place, despite the company's incident update page indicating that they're slated for May 13.
When reached for comment, an Instructure representative pointed CNET to the company's official incident page.
A similar data breach happened to PowerSchool in 2024. Despite paying the ransom, customers were still extorted for more money.
Piotr Swat/SOPA Images/LightRocket/Getty ImagesIs the stolen data really destroyed? There's no way to be sureInstructure reached an agreement with the ShinyHunters hackers, defying the conventional wisdom of industry experts and the FBI's cybercrime division. Once the information is out there, paying a ransom doesn't guarantee it'll ever stop moving between bad actors.
Worse still, Instructure's ransom payment might incentivize ShinyHunters or other ransomware hacker groups to look for more victims.
"It's a very worrying example to see such a high-profile incident result in a payment, especially when acknowledged by the victim company in this fashion," said Troy Hunt, founder and CEO of Have I Been Pwned, a website that keeps track of password info exposed by data breaches. "Unfortunately, it's now a very clear example of how crime does pay, and it normalizes the pattern for future criminals and victims alike."
Hunt speculated that the decision was likely influenced by the scope and scale of the incident. This was a high-exposure data breach, and Instructure is subject to pressure from schools and parents, especially since they handle sensitive information related to underage children.
Watch this: What to do if your personal information is part of a data breach
02:41
But at the end of the day, there's no way to guarantee that the stolen data has actually been destroyed -- absolute certainty doesn't exist with ransomware cybercrime.
"There could always be another copy," Hunt said. "Instructure's message about 'shred logs' provides no proof whatsoever that all copies of data were deleted."
Hunt pointed to a similar ransomware attack on the education company PowerSchool in December 2024. Though the company paid a sum in exchange for a supposed video of the hackers deleting the stolen data, copies of the sensitive information were later used to extort teachers for additional money.
We can't be sure whether ShinyHunters will use stolen Instructure customer data in the same way, but there's just no guarantee that they don't still have sensitive data of millions of US students.
If you were affected by the recent Canvas hack, it might be time to look into steps you can take to protect yourself from cybercriminals who may have your personal information.
U.S. House lawmakers are demanding representatives from Instructure, the twice-hacked education software maker, provide information about the company’s response to cyberattacks that allowed hackers to steal the personal data of millions of students worldwide.
The House Homeland Security Committee is investigating the hacks and data breach as it has jurisdiction over government activities relating to homeland security, the committee’s chair, Representative Andrew Garbarino, wrote in a letter to Instructure chief executive Steve Daly. U.S. cybersecurity agency CISA has been called in to help with the incident.
The committee seeks Daly or another senior executive to address how hackers repeatedly broke into Instructure’s systems and to disclose the types of data that were taken, Garbarino said in the letter, which cites TechCrunch’s reporting.
The letter also says lawmakers want to know how the company is responding to the attacks and notifying affected schools and seek to examine the adequacy of its coordination with CISA.
Instructure, which makes the popular Canvas school information portal software, has faced criticism for its response to the attacks, especially after it conceded that the hackers abused the same vulnerability to steal reams of sensitive student data and then deface school login pages.
The company confirmed this week that it “reached an agreement” with the hackers and claimed the hackers provided evidence that they had deleted the stolen data. A representative for the ShinyHunters hackers told TechCrunch that they would not continue to extort the company or its customers, but declined to say how much the company had paid as ransom.
Security experts have long argued that paying hackers only goes on to fund future attacks. Hackers have been known to retain stolen data even after they claim to have deleted it, often in hopes of extorting victims again.
Garbarino said the second breach by the same hackers raises “serious questions about the company’s incident response capabilities and its obligations to the institutions and individuals whose data it holds.”
“The scale and timing of the Instructure breach, and the demonstrated inability of a major educational technology vendor to contain a threat actor following an initial intrusion, are precisely the kind of systemic vulnerabilities this Committee has a responsibility to examine,” Garbarino wrote in the letter.
Instructure has not yet said if it will respond to the letter, or if Daly — or whoever is responsible for cybersecurity at the company — would attend the lawmakers’ closed-door briefing.
Instructure spokesperson Brian Watkins did not respond to TechCrunch’s request for comment on Wednesday.
Updated May 14 to note that lawmakers are seeking a closed-door briefing and not public testimony.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at [email protected].
The US House of Representatives is demanding testimony from representatives of Instructure, the twice-hacked company that owns the education platform Canvas. Lawmakers are seeking answers to explain the company's delayed response to cyberattacks that enabled bad actors to scrape the personal information of millions of students and teachers nationwide.
Instructure revealed this week that it had reached a deal with the hacker group ShinyHunters, under which the hackers would destroy copies of user data and agree not to extort users. ShinyHunters had hacked the platform first in April and again last week, and claimed to have targeted thousands of universities and school districts.
The House Homeland Security Committee said it is investigating the hack alongside the Cybersecurity and Infrastructure Security Agency. CISA has been working with Instructure as one of the "outside forensics experts" the company refers to in its incident FAQs, helping to "contain the activity, investigate and apply additional safeguards."
Now the House committee's chair, Rep. Andrew Garbarino, is examining whether Instructure's coordination with CISA was adequate in this situation. In a letter sent to Instructure CEO Steve Daly, Garbarino, a New York Republican, demanded to know how the company was hacked more than once. The House committee also wants more specific information about the types of sensitive information stolen during the hack.
Instructure said the personal data stolen during the Canvas hack included "information like usernames, email addresses, course names, enrollment information and messages."
The agreement with ShinyHunters called for the hackers to delete the data. Instructure said "there is never complete certainty when dealing with cybercriminals," but that it received digital confirmation, in the form of shred logs, that the stolen data had been deleted.
Instructure cautioned affected Canvas users against individual attempts to contact or bargain with the ShinyHunters group, saying its agreement "covers all impacted Instructure customers."
The hacker group first infiltrated Canvas systems on April 29, using a security flaw tied to Free-For-Teacher accounts. This allowed ShinyHunters to scrape personal information tied to students and educators.
While we don't know exactly how many institutions were affected, the hackers claimed they had targeted more than 9,000 universities and public school districts. Canvas is used in K-12 schools, so it's likely that the breach exposed sensitive information of underage students.
The situation escalated when the hackers cracked Instructure's security for a second time on May 7, leaving a message exposing their illicit activity to anyone attempting to sign in to Canvas. Instructure promptly moved Canvas into maintenance mode, during which students were unable to access the service.
If the ShinyHunters name sounds familiar, it's because it's a well-established collective of ransomware hackers. ShinyHunters is the same team that breached Anodot and absconded with some of Rockstar Games' business data in April.
Its previous targets largely consist of large tech companies like Microsoft, Cisco and AT&T, but the hackers have also ransomed information from insurance companies, credit unions and other institutions that handle sensitive data.
Canvas is currently operational, although the Free-For-Teacher accounts have been temporarily disabled as Instructure continues to investigate the exploit used to breach its systems.
Instructure asked customers to continue monitoring their accounts, though its external forensic partner has "found no evidence that the threat actor currently has access to the platform."
Instructure is organizing a webinar for its customers in order to "detail information about the cyberattack and [Instructure's] activities to harden the system." It's currently unclear when these will take place, despite the company's incident update page indicating that they're slated for May 13.
When reached for comment, an Instructure representative pointed CNET to the company's official incident page.
A similar data breach happened to PowerSchool in 2024. Despite paying the ransom, customers were still extorted for more money.
Piotr Swat/SOPA Images/LightRocket/Getty ImagesIs the stolen data really destroyed? There's no way to be sureInstructure reached an agreement with the ShinyHunters hackers, defying the conventional wisdom of industry experts and the FBI's cybercrime division. Once the information is out there, paying a ransom doesn't guarantee it'll ever stop moving between bad actors.
Worse still, Instructure's ransom payment might incentivize ShinyHunters or other ransomware hacker groups to look for more victims.
"It's a very worrying example to see such a high-profile incident result in a payment, especially when acknowledged by the victim company in this fashion," said Troy Hunt, founder and CEO of Have I Been Pwned, a website that keeps track of password info exposed by data breaches. "Unfortunately, it's now a very clear example of how crime does pay, and it normalizes the pattern for future criminals and victims alike."
Hunt speculated that the decision was likely influenced by the scope and scale of the incident. This was a high-exposure data breach, and Instructure is subject to pressure from schools and parents, especially since they handle sensitive information related to underage children.
Watch this: What to do if your personal information is part of a data breach
02:41
But at the end of the day, there's no way to guarantee that the stolen data has actually been destroyed -- absolute certainty doesn't exist with ransomware cybercrime.
"There could always be another copy," Hunt said. "Instructure's message about 'shred logs' provides no proof whatsoever that all copies of data were deleted."
Hunt pointed to a similar ransomware attack on the education company PowerSchool in December 2024. Though the company paid a sum in exchange for a supposed video of the hackers deleting the stolen data, copies of the sensitive information were later used to extort teachers for additional money.
We can't be sure whether ShinyHunters will use stolen Instructure customer data in the same way, but there's just no guarantee that they don't still have sensitive data of millions of US students.
If you were affected by the recent Canvas hack, it might be time to look into steps you can take to protect yourself from cybercriminals who may have your personal information.