ShinyHunters accessed Salesforce records tied to Infinite Campus in March and later published a 1.2GB archive exposing information on 137,100 school staff accounts. The company maintains that the material consists mainly of publicly available directory data and that no student databases were reached.

In its latest reported effort the group says it leveraged a zero-day flaw in Oracle's PeopleSoft business software to harvest data from more than 100 entities, one of which was the University of Nottingham.
Edtech platforms remain high-value targets for groups like ShinyHunters because Salesforce misconfigurations can expose directory data without touching core student databases.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
ShinyHunters published data from 12.9 million genuine Carhartt accounts after the apparel company refused a $3.3 million ransom. The breach, which also exposed records for more than 15,000 employees, originated from Carhartt's Databricks analytics platform.
ShinyHunters obtained and later leaked personal data belonging to 1.6 million RingCentral accounts after a July breach. The incident touched only a limited portion of the cloud communications provider’s customers and left core services untouched.
ShinyHunters has published files on more than 2.3 million individuals linked to Moody Bible Institute following the college's June disclosure of a cyberattack. The release, which includes personal details and donor paperwork, underscores the crew's pattern of exposing data from targets that decline its ransom requests.
DHS is investigating an unidentified actor's breach of the HSIN platform that took place between late May and early June 2026. The unclassified system supports real-time threat information exchange and security coordination for major events such as the ongoing World Cup, marking the second reported HSIN compromise since the 2023 misconfiguration incident.
Tata Electronics confirmed a cybersecurity incident after extortion group World Leaks published more than 630 GB of data that is overwhelmingly Apple-related according to a file index. The breach affects an Indian contract manufacturer that assembles iPhones and supplies other global tech companies.