Breaches · 91 days ago
The break is in the vendor CRM layer, not the student system itself. That matters because a compromise of Salesforce can still hand attackers names, contact details, and support records even when the core SIS stays untouched.
Infinite Campus says ShinyHunters hit its Salesforce instance in March and did not compromise customer databases. Have I Been Pwned put the exposed scope at about 137,100 accounts, including names, email addresses, employers, job titles, phone numbers, physical addresses, usernames, and support tickets; the company serves more than 3,200 school districts.
The lesson extends beyond one edtech vendor. If staff or customer PII lives in Salesforce, that tenant can become the breach even when the main product database is safe.
1 source covering this story
Infinite Campus data breach affects 137,000 school staff accounts
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March.
Part of the PlainSec briefing for 2026-06-16