The popular K-12 student information system Infinite Campus has disclosed a data breach affecting approximately 137,000 users after the notorious threat actor group ShinyHunters executed a “pay or leak” extortion campaign against the platform in March 2026.
ShinyHunters, a well-known cybercriminal group responsible for numerous high-profile data theft operations, targeted Infinite Campus in what investigators describe as a classic extortion scheme.
The group threatened to publicly release stolen data unless the company met their financial demands. When negotiations presumably failed, ShinyHunters followed through on the threat and published the allegedly stolen dataset online.
Infinite Campus Data Breach Exposed
The leaked data contained 137,000 unique email addresses, along with a range of personally identifiable information (PII), raising immediate concerns about the exposure of sensitive communications between school administrators and the platform’s support teams.
Infinite Campus subsequently issued breach notifications to affected individuals, clarifying the nature of the exposed records.
According to the company, the compromised dataset largely consisted of “names and contact information for school staff,” with the organization noting that “the majority is directory information commonly found on school websites.”
The full scope of exposed data includes email addresses, names, usernames, phone numbers, physical addresses, employer details, job titles, and contents of internal support tickets.
According to Have I Been Pwned reports, Infinite Campus downplayed the sensitivity of some exposed fields; the inclusion of support ticket data is particularly concerning.
Support tickets often contain detailed technical configurations, reported issues, and internal workflow details that threat actors could leverage for follow-on social engineering or targeted phishing campaigns against school district staff.
With over 12 million students and hundreds of thousands of staff members across U.S. school districts relying on the platform, the breach carries significant downstream risk, even if the directly exposed records primarily belong to school personnel.
Exposed staff contact information combined with support ticket data creates a credible attack surface for spear-phishing and business email compromise (BEC) attempts targeting school districts.
The incident follows a broader trend of ransomware and extortion groups increasingly targeting education sector infrastructure, which typically operates with limited cybersecurity resources compared to enterprise environments.
Affected individuals and organizations should immediately reset passwords for Infinite Campus accounts and any accounts that share the same credentials, and enable multi-factor authentication (MFA) on all administrative portals.
Staff should be alerted to heightened phishing risks, particularly emails impersonating Infinite Campus or district IT personnel.
Organizations are also advised to review exposed support ticket histories for sensitive configuration details and to report any suspicious activity to their district’s IT security team without delay.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.