In June 2026, Glendale Community College fell victim to a ShinyHunters extortion campaign in which stolen data was published online after the college declined to pay. The exposed dataset covers roughly 794,000 unique email addresses alongside names, physical addresses, phone numbers, Social Security numbers, and student enrollment details, though the college notes the specific fields affected vary per individual.
The combination of names, contact details, and SSNs makes this breach particularly dangerous for identity theft and downstream social-engineering attacks. Exposed personal identifiers are frequently reused to craft convincing phishing lures or to answer knowledge-based authentication questions, and email addresses harvested here can seed credential-stuffing and account-takeover attempts against affected individuals.
What to take away: organizations should treat leaked PII as fuel for targeted identity attacks—affected users should watch for phishing, enable MFA, and monitor for SSN misuse, while institutions should assume these identifiers will surface in future credential-based intrusion attempts.