Glendale Community College student-records data incident

Glendale Community College investigated potential unauthorized copying of data related to student educational records. Potentially copied student records included identity, education, financial-aid, and health-related information; HIBP lists additional corpus data classes.

Last modified

Summary

  • Environment: Network and student educational records
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed September 9, 2026; updated as evidence emerges.

What happened

Glendale Community College investigated potential unauthorized copying of data related to student educational records. [1]

Impact

Potentially copied student records included identity, education, financial-aid, and health-related information; HIBP lists additional corpus data classes. [1][3]

Documented data types include:

  • Contact information — Email addresses, phone numbers, and physical addresses listed for records in the HIBP incident corpus. [1][3]
  • Clinical information — Health-related information potentially impacted for some individuals according to the college notice. [1][3]
  • Gender information — Gender information listed for records in the HIBP incident corpus. [1][3]
  • Education records — Student educational records and, depending on the individual, financial-aid information potentially copied without authorization. [1][3]
  • Names — Names potentially impacted in the college notice and also listed for the HIBP corpus. [1][3]
  • Dates of birth — Dates of birth listed for records in the HIBP incident corpus. [1][3]
  • Social Security numbers — Social Security numbers potentially impacted for some individuals according to the college notice. [1][3]
  • Driver’s license numbers — Driver’s license numbers potentially impacted for some individuals; HIBP more broadly lists government-issued IDs. [1][3]

A cited record reports 793,925 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a college-confirmed affected-person count; as of 2026-07-11). The notice advised people to review account, benefits, insurance, and credit statements and to report suspicious activity. The college determined that certain data related to student educational records was potentially copied without authorization. HIBP reported that data allegedly obtained from Glendale was later published online. Glendale began notifying potentially impacted individuals, and the California Attorney General published its submitted sample notice. [1][2][3]

Timeline

  1. Documented event

    Incident date stated by Glendale Community College; HIBP separately lists June 15 as its corpus incident date.

    [1][3]
  2. Briefing updated

    This briefing was last reviewed and updated on September 9, 2026.

Threat Group & Attack Vector

The reviewed public evidence does not identify an initial access path.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The notice stated that law enforcement had not delayed it. The college isolated and secured its network and engaged third-party specialists to contain and investigate the activity. The college offered potentially impacted individuals complimentary credit monitoring and identity-protection services. Glendale reviewed its policies and procedures and implemented additional technical safeguards. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]