Instructure Paid Off Its Hackers. The House Homeland Security Committee Wants to Know Why.

Five days after the recompromise of Canvas during finals week, Instructure announced it had "reached an agreement with the unauthorized actor" responsible for the breach. The agreement appears to have involved money. The House Homeland Security Committee has now asked the company's CEO to explain whether federal law enforcement was involved at any point in the decision.
The Receipt
On the evening of Monday, May 12, 2026, Instructure published a statement announcing that the company had "reached an agreement with the unauthorized actor involved with this incident." The agreement, according to the statement, returned all stolen data, provided "digital confirmation of data destruction," and included assurances that "no Instructure customers will be extorted as a result of this incident, publicly or otherwise."
In a separate message to Reuters reporter A.J. Vicens, a representative of ShinyHunters — the criminal organization that publicly took credit for the breach — confirmed: "The company and its customers will not further be targeted or contacted for payment by us."
Two parties to a settlement. One of them is a criminal extortion organization with a documented history of breaking these arrangements. The other is the company that just paid them to make a public commitment they have no legal obligation to honor and no third-party verification to support.
That is the entire artifact. Instructure has not disclosed the amount paid. ShinyHunters declined to answer Reuters' specific questions about the agreement. The "digital confirmation of data destruction" that Instructure cites has not been independently verified, and given the structure of the agreement, cannot be — because ShinyHunters is the only party with access to what was deleted, and ShinyHunters is also the party whose word is the basis for the entire framing.
A ransomware negotiator quoted in the Reuters piece put the financial reality plainly: "It's fair to conclude that some money was sent."
This is not a security event with a resolution. It is a financial transaction with a press release.
The Same Day, Congress Asked Different Questions
Hours after the Instructure settlement announcement, the House Homeland Security Committee sent a letter to Instructure CEO Steve Daly requesting that he or another senior executive brief the committee on the breach. The letter, as reported by Reuters, asked specifically about "the multiple intrusions" (plural — the committee is treating the September 2025 Penn incident and the May 2026 events as a connected pattern), about "the nature and amount of data stolen," about the company's response, and about "the adequacy of the company's coordination with federal law enforcement and CISA."
That fourth item is not a routine inquiry. It is congressional staff signaling, in writing, that they want to know whether Instructure paid a ransom without engaging federal law enforcement first.
CISA — the Cybersecurity and Infrastructure Security Agency at the Department of Homeland Security — issues explicit guidance to ransomware victims discouraging payment, requiring coordination, and warning of OFAC sanctions exposure when payments flow to designated entities. ShinyHunters has been the subject of multiple federal investigations dating back to 2020. Whether the group or any of its operators currently sit on the OFAC list is a matter the Treasury Department's Office of Foreign Assets Control would have to confirm. Whether Instructure asked that question before sending money is precisely what the committee is requesting to know.
An Instructure spokesperson did not immediately respond to Reuters about the congressional inquiry. Nothing to say. Got it.
A promise from criminals is not a defense. A receipt is not accountability. And the students at 9,000 schools whose data was taken are not parties to any of it.
Why a Promise From Criminals Is Not Protection
The settlement Instructure announced rests entirely on two artifacts: the threat actor's claim that data has been deleted, and the threat actor's commitment that Instructure customers will not be re-extorted. Neither artifact is verifiable. Both are predicated on the good faith of an organization that has demonstrated, repeatedly and recently, that good faith is not part of its operating model.
Five specific reasons the "agreement" does not protect students or schools:
- ShinyHunters has broken these promises before, and the public record is recent. In March 2026 — eight weeks before the Canvas incident — the same group demanded a $1 million ransom from the University of Pennsylvania for data stolen through a Canvas-mediated access path the previous September. Penn refused to pay. On March 5, ShinyHunters published 461 megabytes of Penn's internal data, including donor records and confidential memos. The Daily Pennsylvanian reported the publication. The Cloudskope analysis that Brian Krebs cited at KrebsOnSecurity on May 7 traced the September 2025 Penn breach as the structural antecedent to the May 2026 Canvas events. The same actor that punished Penn for non-payment is now offering Instructure customers a verbal commitment of non-extortion. The customers are being asked to trust that this time is different.
- "Digital confirmation of data destruction" is forensically meaningless. There is no third-party validation mechanism for data deletion claims made by a criminal organization. Instructure has not specified what the "digital confirmation" consists of. A screenshot is a digital confirmation. A signed declaration is a digital confirmation. A video purporting to show a hard drive being wiped is a digital confirmation. None of these establishes that data has actually been deleted, or that copies were not retained, or that data was not sold or transferred to affiliated actors before the deletion occurred. The forensic record on ransomware actor "data deletion" claims, across hundreds of public cases since 2019, is consistent: the data is rarely deleted, frequently sold, and reliably reappears when public attention shifts.
- ShinyHunters operates as a federated criminal ecosystem, not a single entity that can guarantee compliance. The group functions through affiliates, sub-leasers, and partnerships with other extortion crews. Any commitment made by "a representative for ShinyHunters" (the exact attribution Reuters reported) binds, at best, that representative. It does not bind affiliated groups, downstream buyers of the data, or successor operations that emerge as old ones get disrupted by law enforcement. The history of ALPHV / BlackCat, LockBit, REvil, and Conti is that disruption of the headline brand does not delete the data, the operators, or the customer lists. It moves them.
- The data was potentially sold before the deletion claim. ShinyHunters' core business model is data brokerage. The group's leak site is the public face; the larger volume of activity is private brokerage of stolen credentials, datasets, and access. Even granting full good faith to the May 12 commitment, there is no mechanism by which Instructure or its customers can verify that copies of the Canvas data did not enter the brokerage market between May 1 and May 12. Eleven days is enough time. Twenty-four hours is enough time.
- The students were not party to the settlement. Instructure's statement says the agreement "covers all affected Instructure customers" and that "there is no need for individual customers to attempt to engage with the unauthorized actor." The phrasing is precise. Instructure is the company. Instructure's customers are the schools, universities, and districts that license Canvas. The actual data subjects — the 275 million students whose names, email addresses, student ID numbers, and messages were exposed — are not Instructure's customers. They are products of Instructure's customers. They are not parties to the agreement. They were not consulted about it. And their FERPA, COPPA, and state-law notification rights are not waivable by a vendor agreement to which they were not signatories.
The Brand-Protection Posture, Confirmed
The pattern across the past twelve days has been consistent enough to be diagnostic. Each public statement Instructure has made about this breach has prioritized one objective: minimizing reputational damage to the company. Each subsequent event has contradicted the prior statement. Each contradiction has been met not with acknowledgment but with a new statement, in the same posture.
- April 30: Initial disruption framed as "limited disruption to tools relying on API keys." Within hours, criminal forums had it correctly characterized as a security incident.
- May 2: CISO Steve Proud declared the incident "contained." It was not contained.
- May 6: Company stated the situation was "resolved with Canvas fully operational and no indication of ongoing unauthorized activity." Twenty-four hours later, the platform was being defaced live at thousands of universities.
- May 7: During the active recompromise visible to millions of students, the public framing was "scheduled maintenance." See the original Cloudskope analysis for the timeline of that day.
- May 8 (per Instructure's own published FAQ): Quiet acknowledgment that the May 7 events were unauthorized actor activity, walking back the May 7 maintenance framing without acknowledging the walk-back. Acknowledgment that the breach began on April 29, not May 1.
- May 12: Settlement announced. The word "ransom" does not appear. The word "payment" does not appear. The word "agreement" is used four times.
This is not communication failure. It is a sequence of choices, made by specific people at specific moments, each of which prioritized the framing most favorable to Instructure's brand over the framing most accurate to its customers' situation. The May 12 announcement is the culmination of that sequence, not a departure from it.
What Congress Is Going to Ask
The House Homeland Security Committee's letter to Steve Daly was not a routine information request. It was a structured demand for accountability that, if Instructure complies, will surface the facts that the company's settlement announcement omitted. Six specific questions the committee will almost certainly press on, based on the framing of the publicly disclosed letter and on standard committee practice for ransomware-related inquiries:
- How much was paid, and from what source? Federal disclosure law for publicly traded companies requires material cybersecurity incidents to be reported via SEC 8-K filings. Instructure is NYSE-listed (INST). A ransom payment of material size is reportable. A ransom payment funded through a cyber insurance policy is reportable. The amount, the source, and the timing of the payment are facts the committee can compel under its existing oversight authority.
- Was federal law enforcement notified before the negotiation began? CISA, the FBI's Cyber Division, and the Department of Justice publish explicit guidance that ransomware victims should contact federal law enforcement before negotiating with extortion groups. The reasons are operational: federal investigators may have ongoing visibility into the group, may be able to trace cryptocurrency payments, and may be able to prevent payment from flowing to sanctioned entities. Failure to notify is not a criminal offense. It is, however, a question that determines whether the company exercised the diligence expected of a regulated entity holding tens of millions of student records.
- Was OFAC compliance verified before payment? The Treasury Department's Office of Foreign Assets Control maintains a list of designated entities to whom payments are prohibited. Ransomware payments to OFAC-listed entities can expose the paying organization to strict-liability civil penalties of up to $250,000 per violation, regardless of intent. ShinyHunters has not been publicly designated as of this writing, but several of the criminal ecosystem actors with which the group has overlapped have been. Whether Instructure conducted OFAC screening before authorizing payment is a question with direct federal-compliance implications.
- What forensic verification was performed on the "digital confirmation of data destruction"? This is the technical version of the question the committee is likely to phrase as: what evidence does the company actually have that the data is gone? If the answer is "the threat actor told us so," the committee will note it.
- What architectural remediation has been implemented to prevent recompromise? Per Instructure's own published FAQ, the root cause of the May 2026 events was the Free-For-Teacher account program, which the company has now discontinued. The committee will want to understand what other architectural assumptions were similarly flawed, what audits have been conducted, and what the company's plan is to verify that the same access pathway cannot be reactivated by the same threat actor or by an affiliate.
- What is the FERPA notification plan? Settlement with the threat actor does not extinguish notification obligations to the parents of K-12 students whose records were exposed under FERPA, or to the institutional officers responsible for those notifications. The committee is likely to ask Instructure to detail its plan for honoring those obligations independent of the "customers will not be extorted" framing the settlement provides.
The Pattern That the Settlement Does Not Address
The most important fact about the May 12 announcement is not what it says about the data. It is what it does not say about the pattern.
ShinyHunters has now successfully compromised Instructure three times in eight months. The same operators, the same access patterns, the same ransom demand, the same response posture. Settlement of the third incident does not address the structural conditions that produced the first and second. Instructure has not publicly disclosed what changed between September 2025 and May 2026, between May 1 and May 7, or between May 7 and May 12. The settlement provides one party — the criminal organization — a financial outcome and a publicly announced commitment of non-recurrence. It provides the other party — the company — a temporary peace and an immediate news cycle. Neither party in the settlement is a student.
The students whose names, email addresses, and messages were exposed receive nothing. Not an apology. Not a notification. Not a participation in the settlement that supposedly now protects them. Their data may have been deleted. Their data may have been copied. Their data may have been sold to a different group before deletion. Their data may reappear in six months, twelve months, or three years, attached to a different breach by a different actor that purchased it on the brokerage market. They will not be told which.
That is the entire story.
A ransom payment to criminals who have demonstrated repeated capability against your platform is not a defensive posture. It is a temporary peace bought at the expense of every customer who will face the same group's next campaign. The data was returned to a company that should not have concentrated it in the first place. The "promise" of non-extortion was given by criminals to a company that just paid them to get it. Neither artifact is worth what Instructure paid for it. The House Homeland Security Committee has now formalized what Cloudskope's analysis, Brian Krebs's reporting, ZDNet's executive playbook, and Reuters' coverage have collectively established: this is no longer a company-specific incident. It is a pattern of conduct that the federal government is preparing to examine in detail. The settlement does not end that examination. It is the reason for it. The data has been "returned." The "promise" has been received. Everyone at the table got what they wanted — except the 275 million people whose information was on it.
Cloudskope advises boards, operating partners, and executive teams navigating cybersecurity incidents where vendor honesty, settlement decisions, regulatory exposure, and federal coordination intersect. Our M&A Cyber Due Diligence, PE-portfolio Risk Advisory, and Executive Risk practices specialize in the structural questions that congressional and regulatory bodies ask after a major breach has been settled — and the architectural conditions that produced the breach in the first place. We help organizations distinguish between paying a ransom and resolving an incident. They are not the same thing.
.png)
.png)