Several #EdTech folks asked me to review the #InfiniteCampus data dump by #ShinyHunters to see if any sensitive student data was leaked as part of it.
I wrote up what I found here: https://databreaches.net/2026/03/28/thankfully-the-infinite-campus-incident-did-not-involve-a-lot-of-non-directory-student-information/
One takeaway for school districts is to remind employees NOT to include student PII or PHI in support tickets to vendors. I've been told it is sometimes required or necessary, but then why weren't tickets like the ones I saw stored with encryption?
#databreach #EduSec #cybersecurity
@mkeierleber @douglevin @funnymonkey
#InfiniteCampus warns of breach after #ShinyHunters claims data theft
@douglevin @brett @mkeierleber
@BleepingComputer @campuscodi
In response to some questions from concerned readers, I contacted SingularityMD with some additional questions about the Jeffco Public Schools attack. I have updated my latest post at:
It seems that Infinite Campus and Google are trying to address some the issues these hacks and media coverage have raised. But how many more districts will become victims before these issues are really addressed?
#databreach #edusec #edtech #infosec #GoogleGroups #InfiniteCampus #extortion