# 137,000 School Staff Accounts Compromised in Infinite Campus Breach
The ShinyHunters extortion gang has claimed responsibility for stealing personal information from more than 137,000 school staff members through a sophisticated Salesforce-based attack on Infinite Campus, one of the most widely deployed K-12 student information systems in North America. The breach, which occurred in March 2026, exposes educators to identity theft, phishing campaigns, and potential credential harvesting on a massive scale—raising serious questions about data security practices in the education sector.
## The Threat
Infinite Campus serves as the backbone for student records, attendance, grades, and administrative functions across thousands of school districts nationwide. The system's integration with Salesforce—a cloud-based customer relationship management platform—created an attack surface that ShinyHunters successfully exploited to extract staff directories containing names, email addresses, phone numbers, and potentially employment records.
What was compromised:
ShinyHunters, a financially motivated threat actor group known for extortion and data trafficking, published portions of the stolen dataset on dark web marketplaces, confirming the breach's authenticity. The group has demanded ransom from the affected organizations and threatened to sell the remaining data if demands are not met.
## Background and Context
Infinite Campus is installed in approximately 3,000+ school districts across 46 U.S. states, making it the second-largest student information system in the country by deployment count. The platform manages mission-critical educational data for millions of students and tens of thousands of staff members daily. School districts rely on Infinite Campus for everything from enrollment management to report card distribution, making any disruption or data compromise a significant operational threat.
The breach represents the latest incident in a growing pattern of attacks against education infrastructure. Schools have historically been viewed as softer targets than enterprise or government organizations, often operating on constrained IT budgets and with fewer dedicated security resources. Recent attacks on education have included:
ShinyHunters has been active since at least 2020 and is known for targeting healthcare systems, financial institutions, and retail organizations. The group's pivot toward education represents an evolution in their targeting strategy and underscores the vulnerability of the education sector's digital infrastructure.
## Technical Details
The attack leveraged Salesforce integration weaknesses in the Infinite Campus platform, likely through either compromised API credentials, inadequate access controls, or an unpatched vulnerability in the integration layer. Salesforce-based attacks have become increasingly common as organizations integrate CRM systems with critical applications without implementing proper authentication and authorization controls.
Key aspects of the attack vector:
| Element | Description |
|---------|-------------|
| Entry Point | Salesforce integration with Infinite Campus |
| Attack Type | Credential compromise or API exploitation |
| Data Exfiltration | Bulk export of staff directory and contact records |
| Scope | Multi-district compromise affecting 137,000+ accounts |
| Detection | Discovered weeks after initial compromise |
The scale of the breach suggests this was not an isolated incident affecting a single school district, but rather a systemic vulnerability or credential compromise affecting multiple organizations simultaneously. This indicates either a vulnerability in the Infinite Campus-Salesforce integration that could be exploited across multiple deployments, or widespread credential compromise among district administrators who manage these systems.
The fact that ShinyHunters was able to extract contact information in bulk—rather than accessing isolated student records—suggests they gained administrative or service account access, rather than exploiting a front-end application vulnerability.
## Implications
For Educators: School staff whose information was compromised face immediate risks of phishing attacks, credential stuffing, and identity theft. Attackers now possess contact information that can be weaponized for spear-phishing campaigns targeting school district networks. Staff email addresses and phone numbers are particularly valuable because they enable social engineering attacks against the very infrastructure they use daily.
For School Districts: The breach creates cascading liability concerns. Districts must notify affected staff members, navigate state notification laws, and potentially provide credit monitoring services. More significantly, the breach demonstrates a fundamental gap in third-party security practices—Salesforce integration wasn't adequately isolated or monitored.
For Students (Indirect Impact): While student records were not directly compromised in this breach, the compromise of staff accounts creates a potential stepping stone for attackers to access more sensitive data. Attackers with valid staff credentials could potentially escalate access to student information systems, creating serious privacy and legal risks under FERPA (Family Educational Rights and Privacy Act).
Legal and Compliance Exposure: Schools operating in states with data breach notification laws must comply with notification timelines and transparency requirements. Additionally, school districts may face litigation from affected staff members and potential investigations from state attorneys general.
## Recommendations
For School Districts:
1. Immediate Actions
- Conduct a comprehensive audit of all Salesforce integrations with student information systems
- Force password resets for all administrative and service accounts
- Review access logs for unauthorized activity post-March 2026
- Notify affected staff members in accordance with state notification laws
2. Technical Hardening
- Implement multi-factor authentication (MFA) on all Salesforce accounts with Infinite Campus integration
- Deploy API gateway controls and rate limiting on Salesforce connections
- Enable comprehensive audit logging on all Salesforce API access
- Segment Salesforce instances from core student data systems using network controls
3. Operational Changes
- Establish a dedicated security team responsible for third-party integrations
- Conduct quarterly security reviews of all cloud integrations
- Implement zero-trust access policies for administrative accounts
- Require signed security assessments from vendors before integration approval
4. Staff Protection
- Provide phishing awareness training to all staff, with emphasis on school-specific threats
- Implement email filtering and anomaly detection for suspicious messages from external sources
- Establish a reporting mechanism for phishing attempts
- Offer free credit monitoring for affected employees
For Infinite Campus and Salesforce:
---
## HackWire Analysis
This breach reveals a critical vulnerability in how education technology vendors approach cloud integrations—they've prioritized seamless data flow over security isolation. Infinite Campus' reliance on direct Salesforce integration, without adequate compartmentalization or authentication controls, created a single point of failure affecting tens of thousands of educators simultaneously.
What makes this incident particularly alarming is who ShinyHunters is: a financially motivated extortion group, not a state-sponsored actor. This means they will aggressively monetize this data. The fact that they're releasing portions on dark web marketplaces suggests the data has high value in criminal underground markets—school staff email addresses and phone numbers are perfect for credential stuffing campaigns, spear-phishing, and business email compromise.
Schools have historically received less scrutiny from security researchers and less investment in defensive tools than enterprise or healthcare organizations. This creates a perception among threat actors that districts are easier targets with lower detection rates. The education sector urgently needs industry standards for vendor security assessments and mandatory integration security requirements—right now, there are none. Without intervention, we can expect more education vendors to be compromised in similar fashion.
The recommendation isn't revolutionary: MFA, API rate limiting, and access logging are table stakes in financial services. Education technology needs to catch up.
— HackWire Editorial
---
## Related Coverage