← Knowledge Center
Breach

Houston City College breach exposes 831,642 accounts in ShinyHunters extortion

Houston City College was hit in June 2026 by a ShinyHunters “pay or leak” extortion campaign. After the college apparently declined to pay, the stolen data was published publicly and later indexed by Have I Been Pwned. The dump contains roughly 832,000 unique email addresses alongside names, physical addresses, phone numbers, academic records, and other personal details covering both current students and alumni.

While no passwords or credentials were reported in this exposure, the combination of email addresses, phone numbers, and rich personal data provides ready material for targeted phishing, credential-stuffing, and social-engineering attacks against affected individuals and against the institution’s own identity systems.

What to take away: breaches like this fuel downstream account-takeover attempts. Organizations should watch for leaked institutional email addresses appearing in phishing and password-spray campaigns, and enforce MFA and monitoring on any accounts tied to exposed identities.

Primary source

Have I Been Pwned

Read at haveibeenpwned.com ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.