Infinite Campus data breach affects 137,000 school staff accounts
In March 2026, the ShinyHunters extortion group stole personal information from over 137,000 school staff accounts by targeting the Salesforce instance used by Infinite Campus, a widely used K-12 student information system. The stolen data primarily included names, email addresses, phone numbers, physical addresses, job titles, usernames, and support tickets. Infinite Campus stated that the majority of the exposed data was directory information commonly found on school websites and that there was no evidence of customer database compromise. The breach is part of a broader pattern of attacks by ShinyHunters on Salesforce customers. Infinite Campus notified affected customers but did not attribute the attack to a specific group in their notification.
AI Analysis
Technical Summary
The ShinyHunters extortion gang conducted a data theft attack in March 2026 targeting the Salesforce instance of Infinite Campus, an education technology company serving over 3,200 U.S. school districts. The breach exposed personal information from approximately 137,100 school staff accounts, including names, contact details, job titles, and support tickets. Infinite Campus confirmed the data mainly consisted of publicly available directory information and reported no evidence of customer database compromise. The attackers leaked a 1.2GB archive of Salesforce records on their data leak site. This incident aligns with ShinyHunters' ongoing campaign against Salesforce customers and follows similar high-profile breaches in the education sector.
Potential Impact
The breach exposed personally identifiable information (PII) of more than 137,000 school staff members, including names, email addresses, phone numbers, physical addresses, job titles, usernames, and support tickets. Although Infinite Campus indicated that most of the data was publicly available directory information and there was no evidence of customer database compromise, the exposure of such data could facilitate targeted phishing or social engineering attacks against affected individuals. No direct evidence of further exploitation or broader system compromise has been reported.
Mitigation Recommendations
No official patch or remediation guidance has been provided by Infinite Campus regarding this breach. Infinite Campus has notified affected customers and stated that the exposed data largely consists of publicly available information. Organizations using Infinite Campus should follow any guidance from the vendor and monitor communications for updates. Given the nature of the breach, affected individuals should be advised to remain vigilant against phishing and social engineering attempts. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Infinite Campus data breach affects 137,000 school staff accounts
Description
In March 2026, the ShinyHunters extortion group stole personal information from over 137,000 school staff accounts by targeting the Salesforce instance used by Infinite Campus, a widely used K-12 student information system. The stolen data primarily included names, email addresses, phone numbers, physical addresses, job titles, usernames, and support tickets. Infinite Campus stated that the majority of the exposed data was directory information commonly found on school websites and that there was no evidence of customer database compromise. The breach is part of a broader pattern of attacks by ShinyHunters on Salesforce customers. Infinite Campus notified affected customers but did not attribute the attack to a specific group in their notification.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ShinyHunters extortion gang conducted a data theft attack in March 2026 targeting the Salesforce instance of Infinite Campus, an education technology company serving over 3,200 U.S. school districts. The breach exposed personal information from approximately 137,100 school staff accounts, including names, contact details, job titles, and support tickets. Infinite Campus confirmed the data mainly consisted of publicly available directory information and reported no evidence of customer database compromise. The attackers leaked a 1.2GB archive of Salesforce records on their data leak site. This incident aligns with ShinyHunters' ongoing campaign against Salesforce customers and follows similar high-profile breaches in the education sector.
Potential Impact
The breach exposed personally identifiable information (PII) of more than 137,000 school staff members, including names, email addresses, phone numbers, physical addresses, job titles, usernames, and support tickets. Although Infinite Campus indicated that most of the data was publicly available directory information and there was no evidence of customer database compromise, the exposure of such data could facilitate targeted phishing or social engineering attacks against affected individuals. No direct evidence of further exploitation or broader system compromise has been reported.
Mitigation Recommendations
No official patch or remediation guidance has been provided by Infinite Campus regarding this breach. Infinite Campus has notified affected customers and stated that the exposed data largely consists of publicly available information. Organizations using Infinite Campus should follow any guidance from the vendor and monitor communications for updates. Given the nature of the breach, affected individuals should be advised to remain vigilant against phishing and social engineering attempts. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/infinite-campus-data-breach-affects-137-000-school-staff-accounts/","fetched":true,"fetchedAt":"2026-06-15T12:45:13.453Z","wordCount":770}
Threat ID: 6a2ff3d90b89be688802b09c
Added to database: 6/15/2026, 12:45:13 PM
Last enriched: 6/15/2026, 12:45:22 PM
Last updated: 6/15/2026, 2:01:19 PM
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.