Infinite Campus data breach affects 137,000 school staff accounts
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March. [...]
AI Analysis
Technical Summary
The ShinyHunters extortion gang conducted a data theft attack in March 2026 targeting the Salesforce instance of Infinite Campus, an education technology company serving over 3,200 U.S. school districts. The breach exposed personal information from approximately 137,100 school staff accounts, including names, contact details, job titles, and support tickets. Infinite Campus confirmed the data mainly consisted of publicly available directory information and reported no evidence of customer database compromise. The attackers leaked a 1.2GB archive of Salesforce records on their data leak site. This incident aligns with ShinyHunters' ongoing campaign against Salesforce customers and follows similar high-profile breaches in the education sector.
Potential Impact
The breach exposed personally identifiable information (PII) of more than 137,000 school staff members, including names, email addresses, phone numbers, physical addresses, job titles, usernames, and support tickets. Although Infinite Campus indicated that most of the data was publicly available directory information and there was no evidence of customer database compromise, the exposure of such data could facilitate targeted phishing or social engineering attacks against affected individuals. No direct evidence of further exploitation or broader system compromise has been reported.
Mitigation Recommendations
No official patch or remediation guidance has been provided by Infinite Campus regarding this breach. Infinite Campus has notified affected customers and stated that the exposed data largely consists of publicly available information. Organizations using Infinite Campus should follow any guidance from the vendor and monitor communications for updates. Given the nature of the breach, affected individuals should be advised to remain vigilant against phishing and social engineering attempts. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Infinite Campus data breach affects 137,000 school staff accounts
Description
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ShinyHunters extortion gang conducted a data theft attack in March 2026 targeting the Salesforce instance of Infinite Campus, an education technology company serving over 3,200 U.S. school districts. The breach exposed personal information from approximately 137,100 school staff accounts, including names, contact details, job titles, and support tickets. Infinite Campus confirmed the data mainly consisted of publicly available directory information and reported no evidence of customer database compromise. The attackers leaked a 1.2GB archive of Salesforce records on their data leak site. This incident aligns with ShinyHunters' ongoing campaign against Salesforce customers and follows similar high-profile breaches in the education sector.
Potential Impact
The breach exposed personally identifiable information (PII) of more than 137,000 school staff members, including names, email addresses, phone numbers, physical addresses, job titles, usernames, and support tickets. Although Infinite Campus indicated that most of the data was publicly available directory information and there was no evidence of customer database compromise, the exposure of such data could facilitate targeted phishing or social engineering attacks against affected individuals. No direct evidence of further exploitation or broader system compromise has been reported.
Mitigation Recommendations
No official patch or remediation guidance has been provided by Infinite Campus regarding this breach. Infinite Campus has notified affected customers and stated that the exposed data largely consists of publicly available information. Organizations using Infinite Campus should follow any guidance from the vendor and monitor communications for updates. Given the nature of the breach, affected individuals should be advised to remain vigilant against phishing and social engineering attempts. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/infinite-campus-data-breach-affects-137-000-school-staff-accounts/","fetched":true,"fetchedAt":"2026-06-15T12:45:13.453Z","wordCount":770}
Threat ID: 6a2ff3d90b89be688802b09c
Added to database: 06/15/2026, 12:45:13 UTC
Last enriched: 06/15/2026, 12:45:22 UTC
Last updated: 07/30/2026, 20:27:01 UTC
Views: 127
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.