Vendor Risk
Instructure Paid Off Its Hackers. The House Homeland Security Committee Wants to Know Why.
On May 12, 2026, Instructure announced a settlement with the ShinyHunters criminal organization that breached its Canvas platform, claiming that all stolen data has been "returned" and that the threat actor has provided "digital confirmation of data destruction." The same day, the House Homeland Security Committee sent a letter to Instructure CEO Steve Daly requesting a briefing on the breach response and on the adequacy of coordination with federal law enforcement and CISA. A settlement is not a resolution. A promise from criminals is not a defensive posture. The pattern of conduct that produced three breaches in eight months has not been addressed. The students at 8,809 schools whose data was taken were not parties to the agreement that supposedly now protects them.
275M Users Exposed in Canvas/Instructure Breach
275 million users exposed. 8,809 schools down. Instructure calls it 'scheduled maintenance.' Inside the Canvas breach and the EdTech disclosure failure.
ADT 2026 Breach: Customer Trust Was the Breach
The ADT 2026 breach didn't compromise the alarm systems. It compromised the customer data underneath — and the vishing campaign that followed showed the real risk.
Frost Bank and the New Vendor-Risk Reality
The Frost Bank vendor breach: what happens when a payment processor's third-party software fails. The vendor-risk reality boards and audit committees own.
Ransomware Trends: Q2 2026 Analysis
Q2 2026 ransomware analysis: the operator economics, targeted sectors, cryptocurrency flow, and regulatory responses now reshaping breach disclosure practice.
What Is SOC 2 Compliance? An Executive Guide
SOC 2 for executives: what auditors test, what consultants charge, what boards need to know — and why Type II is what enterprise buyers require.
.png)