ফরেনসিক বিশ্লেষণ
Houston City College compromised in ShinyHunters extortion campaign exposing 831,642 accounts
In June 2026, Houston City College was targeted in a cyber extortion campaign by the threat actor group ShinyHunters. The extortionists published stolen institution records online after the college was targeted. The exposed data includes 831,642 records containing current student and alumni email addresses, names, phone numbers, physical addresses, dates of birth, genders, citizenship statuses, and academic records.
gemini-3.6-flash লিখেছেসূত্রগুলো দেখুন
What happened
In June 2026, Houston City College was targeted by the cybercrime extortion group ShinyHunters in a pay-or-leak campaign. The threat group exfiltrated internal records from the institution and demanded payment under threat of releasing the stolen data publicly[1][2].
After the institution did not comply with the extortion demand, ShinyHunters published the exfiltrated dataset online[1][2]. The leak impacted both current students and alumni of the college system[1].
How it came to light
The incident came to light on June 16, 2026, when ShinyHunters publicly listed Houston City College on its dark web leak site as part of a campaign targeting educational organizations.
The stolen dataset was processed and officially added to the Have I Been Pwned breach notification registry on July 28, 2026[5][6]. The cataloged entry confirmed the compromise of unique account records linked to the institution's domain, hccs.edu[7][8].
What was exposed
The breach exposed 831,642 unique user records, which included approximately 832,000 unique email addresses. The affected records belonged to current students and alumni[1].
The compromised data fields included full names, physical addresses, phone numbers, email addresses, dates of birth, genders, citizenship statuses, and academic records[1][7][8]. Passwords and financial account details were not reported as exposed in the dataset[7][8].
Root cause
The specific intrusion vector and underlying system vulnerability that facilitated the exfiltration of data from Houston City College have not been publicly disclosed.
What to do if you were affected
Individuals whose data was involved should watch for targeted phishing emails, telephone scams, and fraudulent mailings. Threat actors frequently leverage exposed names, email addresses, phone numbers, and academic histories to perform convincing social engineering attacks[8].
Because full names, physical addresses, dates of birth, and citizenship statuses were exposed, impacted students and alumni should monitor their credit reports and financial accounts for unauthorized activity. Placing a fraud alert or credit freeze with major credit reporting agencies can reduce the risk of identity theft.
Affected individuals should verify their exposure status using verified breach notification platforms and ensure multi-factor authentication is enabled across all personal accounts.
সূত্র
উপরের প্রতিটি সংখ্যাযুক্ত চিহ্ন এই সূত্রগুলোর কোনো একটিকে নির্দেশ করে। লিঙ্কগুলো নতুন ট্যাবে খোলে; এগুলো তথ্যসূত্র, অনুমোদন নয়।