# Infinite Campus Data Breach

## What Happened

In March 2026, the student information system [Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign](https://www.bleepingcomputer.com/news/security/infinite-campus-warns-of-breach-after-shinyhunters-claims-data-theft/). The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses, and support tickets. [Infinite Campus subsequently sent notifications](https://www.reddit.com/r/k12sysadmin/comments/1s12xx7/infinite_campus_incident/), advising that the exposed data largely consisted of "names and contact information for school staff" and that "the majority is directory information commonly found on school websites".

## Compromised Data
- Email addresses
- Employers
- Job titles
- Names
- Phone numbers
- Physical addresses
- Support tickets
- Usernames

## Recommended Actions

### Breach Overview
- Affected Accounts: 137.1 thousand
- Breach Occurred: March 2026
- Added to HIBP: 15 Jun 2026

## Recommended Actions

##### Change Your Password
If you haven’t already changed the password affected by this breach, do so immediately on every account where it was used.

##### Enable Two-Factor Authentication
Wherever 2FA is supported, add an extra layer of security to your account.
