Houston City College suffered a data breach tied to the ShinyHunters threat group after attackers allegedly stole institutional data and used a "pay or leak" extortion tactic. When the demand was reportedly not met, the data was published publicly and on underground forums, exposing about 832,000 unique email addresses linked to current students and alumni.
The leaked records reportedly included names, home addresses, phone numbers, academic records, and other personal information, creating elevated risks of identity theft, phishing, and long-term privacy harm. The incident adds to a broader pattern of financially motivated attacks against educational institutions, where legacy systems, decentralized IT environments, and limited security budgets can increase exposure to data theft and extortion.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
After the extortion demand was reportedly not met, the attackers allegedly published the stolen Houston City College data publicly or on underground forums. The exposed information reportedly included 832,000 unique email addresses along with names, addresses, phone numbers, and academic records.
In June 2026, Houston City College was targeted in a ShinyHunters "pay or leak" extortion campaign in which attackers allegedly obtained data from the college. The incident reportedly affected about 832,000 students and alumni.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.