U.S. Sens. Tommy Tuberville and Bill Cassidy are demanding answers from education technology company Instructure after a cybersecurity incident involving its Canvas learning management system exposed …
This item is available in full to subscribers.
Please log in to continue |
U.S. Sens. Tommy Tuberville and Bill Cassidy are demanding answers from education technology company Instructure after a cybersecurity incident involving its Canvas learning management system exposed data connected to an estimated 275 million students, teachers and families worldwide.
Tuberville, an Alabama Republican who chairs the Senate Subcommittee on Education and the American Family, and Cassidy, a Louisiana Republican who chairs the Senate Health, Education, Labor and Pensions Committee, sent a letter Wednesday, May 13, to Instructure CEO Steve Daly raising concerns about the company’s cybersecurity protections and response to the breach. The letter can be found at www.tuberville.senate.gov.
Canvas, the most widely used learning management system in the United States, is used by about 30 million people and more than 8,000 school districts, colleges and universities for coursework, communication and administrative functions. The outage and breach occurred during finals and graduation season, disrupting schools across the country.
According to the senators, unauthorized actors gained access to usernames, email addresses, course names, enrollment information and messages.
“Cybersecurity threats are one of the most significant risks currently affecting the safety and security of our most sensitive information,” the senators wrote. “At a time when hostile actors are increasingly using sophisticated tactics leveraging artificial intelligence, it is essential for the education technology sector to take meaningful steps to safeguard student and consumer information.”
The lawmakers said the incident highlighted growing risks facing schools and educational institutions that rely heavily on digital platforms.
The senators also pointed to Instructure’s previous cybersecurity issues, noting the company experienced another incident in 2025. They cited recent reports indicating the current breach stemmed from two separate attacks on the company’s systems.
In the letter, Tuberville and Cassidy pressed Instructure for details about its cybersecurity and physical security protocols, when the company first became aware of the attack and when federal agencies were notified.
They also questioned whether personally identifiable information was compromised and asked how Instructure is communicating with affected users, including parents and guardians of children under 18.
“Additional transparency is needed regarding what information hostile actors accessed, what measures Instructure had implemented prior to the incident to protect sensitive information and what steps the company intends to take going forward to address vulnerabilities and improve its security infrastructure,” the senators wrote.
The lawmakers also sought information about reports that some schools experienced defacement attacks in which hackers publicly identified affected institutions. They asked how many customers may have been impacted and what support Instructure is providing to help schools regain access to affected systems.
The senators additionally requested details about a recent agreement Instructure said it reached with the “unauthorized actor involved in this incident,” including the return of stolen data and “digital confirmation of data destruction.”
Tuberville and Cassidy asked the company to disclose the terms of that agreement, what data was covered and whether investigators believe additional data may have been taken outside the agreement.
The senators requested Instructure respond to their questions by May 28.