Back to Exposure Report
EdTech / K-12 June 26, 2026 United States

Infinite Campus

ShinyHunters compromises employee Salesforce account at major student information system provider. 137,000 accounts leaked after ransom negotiations fail.

Email addressesNamesPhone numbersPhysical addressesJob titlesUsernamesSupport tickets
1

What happened?

In March 2026, ShinyHunters gained access to an Infinite Campus employee's Salesforce account. Infinite Campus is one of the largest Student Information System (SIS) providers in the United States, serving K-12 school districts with enrollment management, student records, and administrative functions.

According to notifications sent to affected individuals, the breach occurred on March 18, 2026. When extortion negotiations failed, ShinyHunters published the stolen data. The leak contained 137,123 unique accounts—students, workers, and administrators whose information passed through Infinite Campus support systems.

2

What data was actually inside?

137,123 records containing email addresses, names, phone numbers, physical addresses, job titles, usernames, and support ticket contents. The Salesforce environment held customer support data—meaning communications between school districts and Infinite Campus about their SIS implementations.

Support tickets often contain more than intended. Troubleshooting student record issues, resolving access problems, discussing system configurations—these conversations can include student names, enrollment details, technical infrastructure information, and administrative credentials. The support system becomes an unintended repository of sensitive information.

3

Who gets hurt and how?

School district administrators who contacted Infinite Campus support. IT staff whose usernames and contact details are exposed. Potentially students and families whose information appeared in support ticket discussions—anyone whose record was referenced while troubleshooting an issue.

Email addresses and names enable targeted phishing. Physical addresses and phone numbers enable social engineering. Job titles reveal who has administrative access to student data. For threat actors interested in education sector targets, this is reconnaissance data—a map of who controls student information systems across school districts.

4

What did they think they were doing right?

Infinite Campus is a major SIS vendor trusted by thousands of school districts. Using Salesforce for customer relationship management is standard enterprise practice. Both are established platforms with security resources.

But the attack vector was a single employee account. One compromised credential provided access to the Salesforce environment. The security of 137,000 records depended on the credential hygiene of individual employees—not on platform security. Phishing, credential stuffing, or infostealer malware on one person's device becomes a breach of everyone in the CRM.

5

What did they not know about their own data?

Support systems accumulate data across years of customer interactions. Old tickets, closed cases, resolved issues—they persist unless actively deleted. How many of those 137,000 records represented active support relationships versus historical interactions from years past?

Salesforce environments grow organically. Ticket attachments, email threads, account histories. Each support interaction adds data. Without retention policies that expire old tickets and purge unnecessary attachments, the CRM becomes an expanding archive of customer information—and all of it is in scope when an attacker gains access.

If you use Salesforce, you probably have the same data types—emails, names, addresses, phone numbers. Do you know which fields contain PII?

6

What does attribution look like the morning after?

Infinite Campus sent notifications to affected individuals. FERPA implications must be assessed—if student records appeared in support tickets, educational record protections apply. Each school district that used Infinite Campus support must determine whether their students or staff were affected.

This is a vendor breach affecting customers downstream. School districts chose Infinite Campus as a trusted SIS provider. Now they must communicate to parents and staff about a breach they didn't cause but are affected by. The reputational and operational burden cascades from vendor to customer to community.

7

What would have changed the outcome?

Understanding exactly what sensitive data accumulated in support systems—and implementing retention policies that limited historical exposure.

CRM platforms are designed to remember customer interactions. That's valuable for service continuity. It becomes a liability when a single credential compromise exposes every interaction ever logged. Data inventory identifies what's accumulating. Retention enforcement limits how far back the exposure extends. The organizations that minimize CRM data exposure are the ones that knew what was in there before an attacker found out.

Infinite Campus found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.