Houston City College Breach: 831K Records Exposed (2026)
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal infor...
Overview
On June 15, 2026, the threat group known as ShinyHunters announced a “pay or leak” extortion campaign against Houston City College, a public community college in Texas. When the college did not pay the demanded ransom, the group published a trove of stolen data publicly. The breach exposes 831,642 unique records - primarily email addresses, names, addresses, phone numbers, academic records, and other personal information - affecting both current students and alumni. The data has been indexed on Have I Been Pwned, confirming its authenticity and broad distribution.
What Was Exposed
The stolen dataset includes the following personal information per record:
- Email addresses - 831,642 unique entries, the primary identifier used by ShinyHunters to validate the leak.
- Full names
- Physical addresses (home or mailing)
- Phone numbers
- Academic records - including course enrollments, grades, graduation years, and disciplinary notes.
Notably, the breach does not appear to include Social Security numbers or financial account data, but the combination of contact information and academic history is sufficient for targeted phishing, identity theft, and vishing (voice phishing) attacks.
How the Breach Happened
ShinyHunters claimed responsibility for the breach, but the exact attack vector has not been confirmed by Houston City College as of this writing. The group frequently operates by exploiting misconfigured cloud storage (e.g., unsecured S3 buckets), compromised credentials from reused passwords, or SQL injection vulnerabilities in legacy web applications. Given the broad scope of data (academic records spanning years), the attacker likely gained access to a central student information system or a data warehouse rather than a single web application. This incident mirrors similar ShinyHunters extortion campaigns targeting other educational institutions, including over 60 colleges and universities in previous years.
Account Takeover & Phishing Risks
The exposed email addresses are the most immediate risk. With email addresses and names, threat actors can:
- Send highly personalized phishing emails that appear to come from Houston City College (e.g., “Verify your enrollment status” or “New academic policy update”).
- Attempt credential reuse attacks against other services - students and alumni who use the same password for their college portal on banking or social media accounts are at risk.
- Use phone numbers for smishing (SMS phishing) and vishing calls, posing as college administrators or IT support.
What to Do Right Now
Affected individuals - all current students, faculty, and Houston City College alumni - should take these steps immediately:
- Change your college portal password - use a strong, unique password. Do not reuse this password anywhere else.
- Enable multi-factor authentication (MFA) on your college account if available. If not, enable it wherever else you can (email, banking, social media).
- Check your email inbox for suspicious messages - do not click links or open attachments in unsolicited emails claiming to be from the college. Forward any phishing attempts to [email protected].
- Monitor your credit reports for free at annualcreditreport.com - while SSNs are not confirmed, secondary identity theft is possible if other databases become linked.
How to Check If You’re Affected
You can verify whether your email address was included in this breach by visiting Have I Been Pwned and entering your email address. If your email appears in the search results, you are affected and should follow the recommendations above. The breach has been indexed with 831,642 entries.
Security Insight
This breach underscores a troubling pattern in higher education cybersecurity: institutions often prioritize firewall and perimeter defenses while neglecting internal access controls and offboarding procedures. Houston City College, like many community colleges, faced resource constraints that likely limited its ability to monitor for lateral movement after initial compromise. The ShinyHunters group specifically targets organizations with weak data management practices - the exposure of 12 years of academic records suggests that the college lacked data retention policies or audit trails to detect exfiltration in progress.
Further Reading
Investigate Breaches Safely with NordVPN
Researching exposed data, paste sites, or threat actor infrastructure? Route your OSINT traffic through a VPN to avoid attribution and keep your investigation IP separate from your corporate network.
Get NordVPN for ResearchAffiliate link — we may earn a commission at no extra cost to you.
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In June 2026, Glendale Community College was the target of a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from Glendale was later published online and included almost 800k unique email addresses along with various other data fields, including names, addresses, phone number...
In July 2026, electronic test and measurement equipment company Fluke was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published more than 100GB of data allegedly taken from the company. The corpus contained largely corporate contact information, including ove...
In June 2026, a party claiming to have access to data from Goose Creek Candle Company sent emails to a number of the company's customers , claiming the company had a security vulnerability and suffered a data breach. The data was subsequently sent to Have I Been Pwned and contained 6.6M unique email...
In June 2026, Moody Bible Institute was targeted by a ShinyHunters "pay or leak" extortion campaign . Over 2.3M unique email addresses and other personal data were later published publicly, including names, physical addresses, phone numbers, dates of birth and other information relating to donors, s...