---
title: "Glendale Community College student-records data incident"
description: "Evidence-backed account of Glendale Community College student-records data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-09-09"
canonical_url: "https://www.ally.security/incidents/glendale-community-college-student-records-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/glendale-community-college-student-records-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/glendale-community-college-student-records-data-incident-2026/stix.json"
---

# Glendale Community College student-records data incident

Glendale Community College investigated potential unauthorized copying of data related to student educational records. Potentially copied student records included identity, education, financial-aid, and health-related information; HIBP lists additional corpus data classes.

Last modified Sep 9, 2026 · 3 sources

## Summary

- **Environment:** Network and student educational records
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

[Glendale Community College](https://www.glendale.edu/) investigated potential unauthorized copying of data related to student educational records. [1](#source-1)

## Impact

Potentially copied student records included identity, education, financial-aid, and health-related information; HIBP lists additional corpus data classes. [1](#source-1) [3](#source-3)

Documented data types include:

- Contact information — Email addresses, phone numbers, and physical addresses listed for records in the HIBP incident corpus. [1](#source-1) [3](#source-3)
- Clinical information — Health-related information potentially impacted for some individuals according to the college notice. [1](#source-1) [3](#source-3)
- Gender information — Gender information listed for records in the HIBP incident corpus. [1](#source-1) [3](#source-3)
- Education records — Student educational records and, depending on the individual, financial-aid information potentially copied without authorization. [1](#source-1) [3](#source-3)
- Names — Names potentially impacted in the college notice and also listed for the HIBP corpus. [1](#source-1) [3](#source-3)
- Dates of birth — Dates of birth listed for records in the HIBP incident corpus. [1](#source-1) [3](#source-3)
- Social Security numbers — Social Security numbers potentially impacted for some individuals according to the college notice. [1](#source-1) [3](#source-3)
- Driver's license numbers — Driver's license numbers potentially impacted for some individuals; HIBP more broadly lists government-issued IDs. [1](#source-1) [3](#source-3)

A cited record reports 793,925 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a college-confirmed affected-person count; as of 2026-07-11). The notice advised people to review account, benefits, insurance, and credit statements and to report suspicious activity. The college determined that certain data related to student educational records was potentially copied without authorization. HIBP reported that data allegedly obtained from Glendale was later published online. Glendale began notifying potentially impacted individuals, and the California Attorney General published its submitted sample notice. [1](#source-1) [2](#source-2) [3](#source-3)

## Timeline

### June 16, 2026 — Documented event

Incident date stated by Glendale Community College; HIBP separately lists June 15 as its corpus incident date. [1](#source-1) [3](#source-3)

### September 9, 2026 — Briefing updated

This briefing was last reviewed and updated on September 9, 2026.

## Threat Group & Attack Vector

The reviewed public evidence does not identify an initial access path.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The notice stated that law enforcement had not delayed it. The college isolated and secured its network and engaged third-party specialists to contain and investigate the activity. The college offered potentially impacted individuals complimentary credit monitoring and identity-protection services. Glendale reviewed its policies and procedures and implemented additional technical safeguards. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/glendale-community-college-student-records-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Cyber Security Update

official · Glendale Community College

<https://www.glendale.edu/about-gcc/communications/update/index.html>

<a id="source-2"></a>

### Submitted Breach Notification Sample — Glendale Community College

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-625293>

<a id="source-3"></a>

### Glendale Community College breach record

advisory · Have I Been Pwned · Jul 11, 2026

<https://haveibeenpwned.com/api/v3/breach/GlendaleCommunityCollege>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Organization · 100% confidence · current**  
   June 2026 Glendale Community College cybersecurity incident: Glendale Community College
2. **Resulted In · 100% confidence · current**  
   Glendale Community College incident notification: The notice advised people to review account, benefits, insurance, and credit statements and to report suspicious activity.
3. **Exposed Data Category · 100% confidence · current**  
   Glendale Community College student-records exposure: Contact information
4. **Exposed Data Category · 100% confidence · current**  
   Glendale Community College student-records exposure: Clinical information
5. **Resulted In · 100% confidence · current**  
   Glendale Community College incident notification: The notice stated that law enforcement had not delayed it.
6. **Affected Organization · 100% confidence · current**  
   Glendale Community College student-records exposure: Glendale Community College
7. **Resulted In · 100% confidence · current**  
   June 2026 Glendale Community College cybersecurity incident: The college said it had no reason at that point to believe personally identifiable employee data had been compromised.
8. **Resulted In · 100% confidence · current**  
   June 2026 Glendale Community College cybersecurity incident: The college isolated and secured its network and engaged third-party specialists to contain and investigate the activity.
9. **Resulted In · 100% confidence · current**  
   June 2026 Glendale Community College cybersecurity incident: The college determined that certain data related to student educational records was potentially copied without authorization.
10. **Resulted In · 100% confidence · current**  
   June 2026 Glendale Community College cybersecurity incident: Glendale Community College student-records exposure
11. **Exposed Data Category · 100% confidence · current**  
   Glendale Community College student-records exposure: Gender information
12. **Exposed Data Category · 100% confidence · current**  
   Glendale Community College student-records exposure: Education records
13. **Resulted In · 90% confidence · current**  
   Glendale Community College student-records exposure: HIBP reported that data allegedly obtained from Glendale was later published online.
14. **Resulted In · 100% confidence · current**  
   June 2026 Glendale Community College cybersecurity incident: Glendale Community College incident notification
15. **Exposed Data Category · 100% confidence · current**  
   Glendale Community College student-records exposure: Names
16. **Exposed Data Category · 100% confidence · current**  
   Glendale Community College student-records exposure: Dates of birth
17. **Occurred At · 100% confidence · current**  
   June 2026 Glendale Community College cybersecurity incident: 2026-06-16
18. **Resulted In · 100% confidence · current**  
   Glendale Community College incident notification: Glendale began notifying potentially impacted individuals, and the California Attorney General published its submitted sample notice.
19. **Resulted In · 100% confidence · current**  
   Glendale Community College incident notification: The college offered potentially impacted individuals complimentary credit monitoring and identity-protection services.
20. **Resulted In · 100% confidence · current**  
   June 2026 Glendale Community College cybersecurity incident: Glendale reviewed its policies and procedures and implemented additional technical safeguards.
21. **Exposed Record Count · 100% confidence · current**  
   Glendale Community College student-records exposure: 793,925 record
22. **Exposed Data Category · 100% confidence · current**  
   Glendale Community College student-records exposure: Social Security numbers
23. **Exposed Data Category · 100% confidence · current**  
   Glendale Community College student-records exposure: Driver's license numbers

</details>
