Houston City College Breach Exposes Academic Records and Personal Data of 832,000 People

Houston City College has confirmed a significant data breach after threat actors from the ShinyHunters extortion group published sensitive records belonging to current students and alumni.

The incident, which occurred in June 2026, exposed personal and academic information tied to 832,000 unique email addresses, making it one of the larger EdTech-sector breaches disclosed this year.

The breach stems from a “pay or leak” extortion campaign attributed to ShinyHunters, a threat group known for large-scale data theft operations targeting educational institutions and enterprises.

Houston City College Breach

The group allegedly exfiltrated data from Houston City College’s systems and later published it publicly after the institution reportedly did not meet ransom demands.

The compromised dataset was added to Have I Been Pwned (HIBP) on July 28, 2026, confirming 831.6k affected addresses. The breach itself is believed to have occurred in June 2026, though the exact intrusion vector has not been publicly disclosed.

The exposed dataset includes a mix of personally identifiable information and academic records. This includes names and dates of birth, email addresses and phone numbers, physical addresses, genders and citizenship statuses, and academic records.

The presence of citizenship status and academic history alongside standard contact details raises concerns about targeted phishing, identity theft, and academic fraud risks for affected individuals.

EdTech institutions have become increasingly attractive targets for extortion groups due to their large repositories of sensitive student and alumni data, combined with historically underfunded cybersecurity infrastructure compared to enterprise environments.

This breach fits a broader pattern flagged in recent industry reporting, which notes a surge in education-sector data breaches throughout 2026.

ShinyHunters has previously been linked to breaches involving cloud storage misconfigurations, credential theft, and third-party vendor compromises, tactics that align with the group’s established playbook of exploiting weak access controls to exfiltrate bulk data before extortion attempts.

Individuals confirmed as part of this breach should take several precautionary steps. They should monitor email and financial accounts for phishing attempts referencing academic details, enable multi-factor authentication on all linked accounts, and use a password manager to generate unique, strong passwords, especially if credentials were reused across platforms.

It is also important to watch for identity theft indicators, particularly given the exposure of citizenship status and dates of birth, and to check exposure status via Have I Been Pwned using an associated email address.

Houston City College has not yet issued a detailed public statement confirming the scope of the breach or the remediation steps taken.

As investigations continue, affected students and alumni are advised to remain vigilant for follow-on social engineering attempts leveraging the leaked academic and personal data.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories