On March 18, 2026, the education technology provider Infinite Campus became the latest victim in a ShinyHunters “pay or leak” extortion campaign. The group published a dataset containing 137,000 unique email addresses along with names, phone numbers, physical addresses, employers, job titles, usernames, and support tickets. Although Infinite Campus stated that the majority of the records concerned school staff and largely duplicated information already available on public school websites, the exposure still places real personal details of educators, administrators, and potentially some families into the hands of data traders and harassers.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Infinite Campus
Get alerted the next time Infinite Campus files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Infinite Campus’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Public reporting from Have I Been Pwned confirms the dataset appeared on a leak site operated by ShinyHunters. The company later sent breach notifications explaining that the records primarily contained names and contact information for school staff. Infinite Campus emphasized that most of the data qualified as directory information already visible on school websites. However, the published file also included support tickets and additional fields not normally public. No evidence has surfaced that student academic records or grades were taken.
Why This Matters for You and Your Family
When school staff data appears in a breach, the impact reaches beyond the workplace. Teachers, principals, and administrative personnel often share the same contact details at home. A single leaked phone number or address can be used to locate your family, send harassing messages, or attempt identity theft. Children’s school-related accounts sometimes link back to the same family email or phone, creating an unintended bridge between professional and personal exposure. Even directory information becomes dangerous once it is aggregated with data from other breaches.
The Doxxing and Identity-Chain Implications
Names, physical addresses, and phone numbers serve as anchors that tie disparate online handles together. Threat actors routinely combine this information with usernames and support tickets to map out family relationships, children’s gaming accounts, and social-media profiles. What begins as a professional breach can cascade into doxxing campaigns or account takeovers months later. Credential leaks of this nature frequently surface in subsequent attacks on personal email, banking, or gaming platforms because people reuse passwords across work and home systems.