Infinite Campus Salesforce-account data incident

Unauthorized access to an Infinite Campus employee's Salesforce account and an associated school-staff contact-data exposure. Names and contact information for school staff in the affected Salesforce instance, plus a separately quantified verified HIBP corpus.

Last modified

Summary

  • Environment: Salesforce platform
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to an Infinite Campus employee’s Salesforce account and an associated school-staff contact-data exposure. [2]

Impact

Names and contact information for school staff in the affected Salesforce instance, plus a separately quantified verified HIBP corpus. [1][2]

Documented data types include:

  • Names — Names in Infinite Campus’s stated Salesforce-data boundary and HIBP’s DataClasses. [1][2]
  • Customer service records — Support tickets listed in HIBP for the verified corpus. [1][2]
  • Usernames and account identifiers — Usernames listed in HIBP for the verified corpus; passwords or other authenticators are not asserted. [1][2]
  • Employment information — Employers and job titles listed in HIBP for the verified corpus. [1][2]
  • Contact information — Infinite Campus described school-staff contact information; HIBP lists email addresses, phone numbers, and physical addresses for the verified corpus. [1][2]

A cited record reports 137,123 records (Unique email addresses represented in the verified HIBP corpus; not an Infinite Campus-confirmed number of staff, districts, accounts, support tickets, or affected people; as of 2026-06-15). [1][2]

That evening, the unauthorized actor contacted Infinite Campus and demanded payment in exchange for destroying Salesforce data the actor claimed to possess. [2]

Infinite Campus and its security partners were scanning Salesforce data that may have been accessed and said districts would be contacted directly if an additional concern was found. [2]

Timeline

  1. Documented event

    Date Infinite Campus said the unauthorized actor gained access to the employee Salesforce account.

    [2]
  2. Public disclosure

    Publication date on Infinite Campus’s notice.

    [2]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The incident involved Salesforce platform. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

An unauthorized actor gained access to an Infinite Campus employee’s Salesforce account on the afternoon of March 18, 2026. The targeted Salesforce instance contained names and contact information for school staff; Infinite Campus said the majority was directory information commonly found on school websites. Infinite Campus said it had not engaged and would not engage with the unauthorized actor. Multiple security measures alerted Infinite Campus’s IT and Security teams, and the employee Salesforce account was immediately disabled. As a precaution, Infinite Campus disabled certain services for customers without IP-address restrictions while it evaluated whether sensitive information had appeared in customer communications. Infinite Campus’s ongoing investigation indicated that the actor was not attempting to access and had not accessed any customer databases. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]