Back to Exposure Report
Education June 16, 2026 United States / Illinois

Illinois Central College

ShinyHunters' PeopleSoft campaign hits community college. 28GB of HR and payroll data stolen. Deadline passes. Data leaked.

HR recordsPayroll dataEmployee informationAdministrative records
1

What happened?

On June 15, 2026, ShinyHunters posted Illinois Central College to their leak site, claiming over 28 gigabytes of sensitive HR and payroll data. The attack exploited CVE-2026-35273, the same Oracle PeopleSoft zero-day used against JCPenney, universities, and over 100 other organizations in ShinyHunters' two-week campaign.

ShinyHunters issued a final warning requesting negotiations before proceeding with data publication. When the deadline passed without response, the data was released. Illinois Central College joined Glendale Community College, Moody Bible Institute, and Houston City College as confirmed education sector victims of the PeopleSoft campaign.

2

What data was actually inside?

28 gigabytes of HR and payroll data. PeopleSoft is HR and finance software. In an educational context, this means employee records, faculty information, salary data, tax forms, benefits enrollment, and administrative staff details.

Community colleges employ hundreds of faculty, adjuncts, administrators, and support staff. Each employee has a comprehensive HR record: Social Security numbers, direct deposit information, W-2 history, emergency contacts, benefit selections. 28GB represents substantial documentation across years of employment records.

3

Who gets hurt and how?

Faculty members, adjunct professors, administrative staff, facilities workers, and anyone employed by the college whose data resided in PeopleSoft. Community colleges often employ significant part-time and adjunct workforces—people who may not expect their employment records to surface in a cybercrime leak.

HR data enables identity theft. Payroll data reveals banking relationships. Educational institutions often retain records for years—former employees, retirees, seasonal workers. The exposure extends beyond current staff to anyone whose employment history persisted in the system.

4

What did they think they were doing right?

Using Oracle PeopleSoft—enterprise-grade software deployed by thousands of organizations globally, including 68% of ShinyHunters' identified targets being higher education institutions. PeopleSoft is standard infrastructure for universities and colleges managing HR and finance operations.

But the PeopleSoft zero-day was being exploited before Oracle's June 10 patch. Community colleges—with limited IT budgets and security resources compared to large universities—faced an enterprise software vulnerability they couldn't patch because the patch didn't exist yet. The security of employee data depended on vendor vulnerability response timing.

5

What did they not know about their own data?

28GB is a substantial data volume. How many years of HR records does that represent? How many former employees whose data should have been purged? How many adjuncts who taught a single semester years ago and never returned?

Educational institutions have high staff turnover, especially in adjunct and part-time positions. PeopleSoft accumulates records across hiring cycles, departures, rehires, and retirements. Without active data minimization, the system becomes a historical archive of everyone who ever worked there—and that archive is what attackers take.

If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?

6

What does attribution look like the morning after?

Employee notification across years of records. Illinois state breach notification requirements apply. The college must identify everyone whose data was in the PeopleSoft system—current employees, former employees, retirees—and determine what was exposed.

Community colleges operate on tight budgets. Incident response, forensic investigation, notification mailing, credit monitoring—these costs strain institutions that already face funding pressures. The post-breach burden falls on organizations least equipped to absorb it.

7

What would have changed the outcome?

Inventorying what sensitive employee data accumulated in PeopleSoft over time—and implementing retention policies that minimized historical exposure.

Zero-days hit enterprises and community colleges alike. What determines breach impact is how much data exists when attackers get in. 28GB of HR records suggests years of accumulation without aggressive cleanup. Data minimization before the breach limits what attackers can take. The institutions that survive these incidents are the ones that already knew what they had—and had already deleted what they didn't need.

Illinois Central College found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.