The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

BleepingComputer, Cybernews, UpGuard and others confirm ShinyHunters' March 2026 Salesforce breach of Infinite Campus exposing ~137k staff records.

Sourcing
1source

via BleepingComputer

BleepingComputer · track record
65Stories
100%Verified
2630d
All sources →
Markets
CRM···

Live quote · not investment advice

Home/Tech/ShinyHunters steals data on 137,000 Infinite Campus staff accounts
VERIFIEDBy Xavier Rivera· ·2.5 min read

ShinyHunters steals data on 137,000 Infinite Campus staff accounts

ShinyHunters accessed Salesforce records tied to Infinite Campus in March and later published a 1.2GB archive exposing information on 137,100 school staff accounts. The company maintains that the material consists mainly of publicly available directory data and that no student databases were reached.

Source:BleepingComputer
Post
ShinyHunters steals data on 137,000 Infinite Campus staff accounts
TL;DRAI · 60 sec read

ShinyHunters breached Infinite Campus Salesforce accounts in March and stole personal details from over 137,000 school staff accounts. The education provider serves 3,200 US districts and 11 million students. The gang later leaked a 1.2GB file containing names, emails, phones, and addresses. Most data consists of public directory information already on school websites.

The ShinyHunters extortion gang breached Salesforce accounts tied to Infinite Campus in March, obtaining personal details linked to more than 137,000 school employees.

Infinite Campus serves millions of students nationwide. The education technology provider supplies its student information system to over 3,200 school districts in the United States and handles records for 11 million students spread across 46 states.

When Infinite Campus alerted customers about the incident that same month, it stopped short of naming any particular threat actor. Officials instead characterized the intruder as "part of a group known for targeting the Salesforce accounts of hundreds of companies."
In its latest reported effort the group says it leveraged a zero-day flaw in Oracle's PeopleSoft business software to harvest data from more than 100 entities, one of which was the University of Nottingham.


Exposed data limited to staff contact details. The company informed those impacted that only names plus contact information for personnel, together with other material already available to the public, had been taken. It stressed that it found no sign of broader access into customer databases.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Infinite Campus added in its notice that the intruders focused solely on its Salesforce environment. "Their target was the Infinite Campus Salesforce instance, consisting of names and contact information for school staff; the majority is directory information commonly found on school websites," it said.

ShinyHunters claims responsibility and leaks data. The gang later took credit on its leak portal and released a 1.2GB bundle of files that reportedly held Salesforce entries bearing personally identifiable information along with assorted internal corporate records. Have I Been Pwned examined the material and determined that records from 137,100 accounts were exposed, encompassing unique names, email addresses, employers, job titles, phone numbers, physical addresses, usernames, and support tickets.

The breach-notification service reported that the actors had published information they said came from Infinite Campus, "containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets." It noted that Infinite Campus later contacted those affected to explain that the released material mainly comprised "names and contact information for school staff" and that most of it could already be located on school websites.

Incident echoes prior edtech breach but with smaller scope. The episode bears resemblance to the PowerSchool intrusion disclosed in December 2024, although consequences diverged sharply because that earlier event touched 62 million students. The individual responsible, a 19-year-old college student from Massachusetts, received a four-year prison sentence following a guilty plea in May 2025.
Over the past year ShinyHunters has repeatedly struck Salesforce customers and asserted that it has taken more than 1.5 billion records through operations against hundreds of organizations, among them the Salesloft Drift hack and the Salesforce Aura campaign. In its latest reported effort the group says it leveraged a zero-day flaw in Oracle's PeopleSoft business software to harvest data from more than 100 entities, one of which was the University of Nottingham.

EXPERT TAKE

Edtech platforms remain high-value targets for groups like ShinyHunters because Salesforce misconfigurations can expose directory data without touching core student databases.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · The Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
data breachedtechShinyHuntersSalesforce
More fromBleepingComputer
  • CISA warns of actively exploited RCE flaws in Joomla extensions

    Tech · 4d
  • OpenAI Temporarily Drops 5-Hour Cap on GPT-5.6 Sol

    Tech · 5d
  • Progress tells ShareFile on-premises users to power down servers over reported threat

    Tech · 7d
More inTech
  • SigNoz 0.133.0 Open Redirect Lets Attackers Steal SSO Tokens

    Tech · 11h
  • Critical Privilege Escalation Flaw Reported in WordPress Plugin Aimogen Pro

    Tech · 11h
  • OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'

    Tech · 1d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Free forever.

MORE IN TECH

SigNoz 0.133.0 Open Redirect Lets Attackers Steal SSO Tokens

SigNoz through 0.133.0 is affected by a reported open redirect in the SSO flow (referenced in NVD as CVE-2026-63094) that lets unauthenticated attackers steal access and refresh tokens from users on Google OAuth, SAML, or OIDC instances. The CVSS 3.1 score of 8.1 from VulnCheck marks it high severity and requires immediate patching on affected self-hosted deployments.

Critical Privilege Escalation Flaw Reported in WordPress Plugin Aimogen Pro

Aimogen Pro for WordPress through version 2.8.4 allows unauthenticated privilege escalation because the aiomatic_call_google_ai_function omits a capability check, letting attackers clear blacklists and run arbitrary PHP such as creating admin accounts. Wordfence rates it critical at CVSS 9.8; the CVE reached NVD on July 17, 2026.

OpenAI admits GPT-5.6 occasionally deletes files – but it's an 'honest mistake'

OpenAI has confirmed that GPT-5.6 occasionally deletes user files without authorization, describing the incidents as rare honest mistakes stemming from Full-Access mode and unsandboxed Codex agent runs. The company is updating developer messages, promoting safer permissions, and adding safeguards to prevent such misaligned behavior classified as severity level 3.