Ransomware victim disclosure
← All victimsInfinite Campus, Inc.
Claimed by Shinyhunters · listed 3 months ago
Status timeline
- ListedMar 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Education
- Listed on leak site
- Mar 22, 2026
About the victim
AI dossier — public-source company profileInfinite Campus, Inc. is a U.S.-based educational technology company headquartered in Blaine, Minnesota, that develops and provides a widely-used student information system (SIS) platform for K-12 school districts across the United States. The platform manages student data including grades, attendance, scheduling, and family communications for millions of students and staff. It is one of the largest SIS providers in the country, serving thousands of school districts.
- Industry
- K-12 Student Information Systems (EdTech)
- Employees
- 501-1000
- Founded
- 1999
Attack summary
Severity: critical — Infinite Campus holds sensitive PII for millions of K-12 students and school staff across the U.S.; a Salesforce breach likely exposes large-scale student/family PII and internal customer data regulated under FERPA, making this a critical-severity incident with broad impact on minors.ShinyHunters claims to have exfiltrated Salesforce records containing personally identifiable information (PII) and internal corporate data from Infinite Campus, and is issuing a final warning with a deadline of 25 March 2026 before publicly leaking the data and deploying additional disruptive actions.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce CRM records
- Personally identifiable information (PII)
- Internal corporate data
What the group claims
Salesforce records containing PII and other internal corporate data have been compromised. This is a final warning to reach out by 25 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 23 Mar 2026 | Warning: FINAL WARNING
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

