Infinite Campus Incident Exposes Data From 137,000 School Staff Accounts | eSecurity Planet

Infinite Campus Incident Exposes Data From 137,000 School Staff Accounts

A breach at Infinite Campus exposed data from 137,000 school staff accounts, highlighting SaaS security risks in education.

Written By
Ken Underhill
Ken Underhill
Jun 16, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A data breach affecting education technology provider Infinite Campus has exposed the personal information of more than 137,000 school staff members. 

The incident occurred after threat actors allegedly compromised the company’s Salesforce environment and leaked stolen records online. 

“The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets,” data breach notification service Have I Been Pwned (HIBP) said in its analysis of the leaked data.

Key Takeaways of the Infinite Campus Incident

  • Infinite Campus says the incident targeted its Salesforce environment, not its student information databases.
  • The breach exposed personal and contact information tied to approximately 137,000 school staff accounts.
  • ShinyHunters claimed responsibility and allegedly leaked a 1.2 GB archive of Salesforce records and internal data.
  • Although student records were not compromised, the exposed data could support phishing and social engineering campaigns.
  • The incident underscores the growing security risks of SaaS platforms and third-party vendors in education.

Inside the Infinite Campus Incident

The incident highlights the growing cybersecurity risks facing schools and other educational institutions that rely heavily on third-party cloud platforms to manage sensitive operational data. 

Infinite Campus is one of the largest student information system (SIS) providers in the United States, serving more than 3,200 school districts across 46 states and supporting approximately 11 million students. 

As educational institutions increasingly rely on cloud-based services, attacks against third-party vendors can expose thousands of customers to risk, even when the schools’ core systems remain secure. 

According to Infinite Campus, the attack targeted the company’s Salesforce environment rather than its student information databases. 

The organization stated that the exposed information primarily consisted of school staff names and contact details, much of which is publicly available through school directories and websites. 

However, the breach still impacted more than 137,000 accounts, underscoring the security risks of SaaS applications.  

Advertisement

ShinyHunters Claims Responsibility 

The ShinyHunters extortion group has claimed responsibility and leaked a 1.2 GB archive of alleged Salesforce records and internal data.  

Have I Been Pwned (HIBP) found the leaked data included names, email addresses, phone numbers, usernames, physical addresses, and support ticket information from approximately 137,100 accounts. 

Potential Risks From the Exposed Data 

Although no student records were compromised, the leaked data could help attackers conduct phishing and social engineering campaigns. 

Infinite Campus has already notified those impacted by the incident.

Reducing Third-Party Security Risk 

As educational organizations continue relying on third-party services, security teams should layer controls and conduct continuous third-party risk assessments.

  • Enforce phishing-resistant MFA and strong conditional access policies for all privileged accounts.
  • Review user, service account, and third-party application permissions regularly and apply least-privilege access controls.
  • Audit OAuth integrations and remove unnecessary or excessive third-party access to SaaS platforms.
  • Monitor SaaS environments for suspicious activity, unusual logins, unauthorized data exports, and signs of account compromise.
  • Enable centralized logging, data loss prevention (DLP), and continuous security monitoring to improve threat detection and response.
  • Conduct regular third-party risk assessments and evaluate the security practices of vendors that handle sensitive data.
  • Test incident response plans through tabletop exercises and ensure SaaS-related breach scenarios are included in response procedures.

Collectively, these steps can help organizations reduce overall exposure and help limit the blast radius of successful incidents.

Growing SaaS Attack Surface 

For security teams, the Infinite Campus incident serves as another reminder that SaaS platforms and third-party providers have become critical components of the enterprise attack surface. 

Even when core systems and sensitive customer data remain untouched, compromised cloud environments can expose valuable information that fuels phishing, social engineering, and other follow-on attacks. 

This growing reliance on third-parties is one reason organizations are using zero trust solutions that help continuously verify users, devices, and access requests.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.