:

INFINITE CAMPUS BREACH EXPOSES 137,000 SCHOOL STAFF

SECURITY DESK2 MIN READ
MON, JUN 15, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The ShinyHunters extortion gang stole personal information from over 137,000 school staff accounts through a Salesforce-based attack on Infinite Campus, a widely used K-12 student information system. The breach occurred in March.

Infinite Campus, a critical platform managing student records for thousands of schools across North America, fell victim to a data theft targeting its Salesforce infrastructure. ShinyHunters, an established extortion operation, accessed sensitive personal information belonging to school employees during the attack. The breach highlights vulnerabilities in widely-adopted educational technology systems that handle confidential student and staff data. Infinite Campus serves as a central repository for administrative information at many K-12 institutions, making it an attractive target for threat actors seeking high-value data. Affected staff members face risks of identity theft and fraudulent activity, given the personal information exposed in the attack. Schools relying on the platform have begun notifying impacted employees and offering credit monitoring services. The incident adds to a growing list of breaches targeting critical infrastructure used by educational institutions. Schools nationwide have increasingly become targets for cybercriminals, with student data and financial systems frequently compromised. Infinite Campus has not released detailed public statements about the breach's scope or remediation efforts. The company has been working with law enforcement and cybersecurity experts to investigate the incident and prevent further unauthorized access. ShinyHunters has a history of high-profile attacks, including previous breaches at major retailers and service providers. The group typically steals data and demands ransom payments, threatening to sell or release information publicly if demands are not met. Schools and districts using Infinite Campus are advised to strengthen authentication protocols, monitor for unauthorized access, and review account activity for suspicious behavior. Educational institutions should also consider implementing additional security measures around sensitive staff and student data. The breach underscores the need for robust security practices among vendors serving the education sector, where budget constraints often limit cybersecurity investments.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.

2H AGOSecurity Desk

A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.

4H AGOIndustry Desk

A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.

9H AGOIndustry Desk

Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.

12H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.