Infinite Campus data breach affects 137,000 school staff accounts

Summary

The ShinyHunters extortion gang has stolen personal information from over 137,000 school staff accounts by targeting the Infinite Campus K-12 student information system in a March data theft attack. The attackers leveraged a Salesforce vulnerability to gain access to the sensitive data.

IFF Assessment

FOE

This data breach exposes sensitive personal information of numerous school staff, posing a risk of identity theft and other malicious activities.

Defender Context

This incident highlights the ongoing risks associated with cloud-based student information systems and the potential for large-scale data exposure. Defenders should be aware of such attacks targeting educational institutions and ensure robust security measures are in place for sensitive data handled by third-party vendors like Salesforce.

Read Full Story →