← Blog

Houston City College Breach: 832K on HIBP

Share on X

June 2026 / HIBP July 28, 2026: Houston City College (HCC), the public community-college system serving Houston, Texas, was named in a ShinyHunters pay-or-leak campaign. After the data was published, Have I Been Pwned indexed 831,642 unique email addresses tied to current students and alumni—making this one of the larger U.S. edtech dumps of mid-2026.

Trade-press summaries, including SecurityAffairs, place the extortion activity around June 16, 2026, the same day Glendale Community College disclosed a parallel ShinyHunters hit. BreachHistory catalogs the HIBP-attested count at houston-city-college-shinyhunters2026.

What happened

ShinyHunters’ 2026 playbook against education targets is familiar: steal a large student-information style dossier, threaten public release unless paid, then dump when negotiations fail—or when publicity alone serves the brand. For Houston City College, the public aftermath is what HIBP verified: a corpus large enough that unique email addresses alone exceed 830,000.

That figure is not a marketing claim from a leak site. It is the count Troy Hunt’s project loaded after processing the published files—the same attestation model BreachHistory uses for Glendale CC (~794K), University of Nottingham (~455K), and other mid-year education breaches.

Some civil litigation coverage has cited a smaller “nearly 69,000 students” figure. Treat that as a lawsuit plaintiff or notice pool, not the full dump. When HIBP and a class-action headline disagree, the verified email/record count in the published dataset is the better catalog denominator until a regulator publishes a different attested census.

What data was exposed

According to the HIBP breach card for Houston City College, the compromised fields include:

  • Names
  • Email addresses
  • Physical addresses
  • Phone numbers
  • Dates of birth
  • Genders
  • Citizenship statuses
  • Academic records

That combination is more dangerous than a bare email list. Date of birth plus address plus citizenship status is enough to craft convincing financial-aid, immigration, or “update your student portal” phishing. Academic records add leverage for transcript and enrollment scams aimed at alumni who have not logged into HCC systems in years.

What was not (yet) attested

Unlike Glendale’s college notice—which explicitly flagged possible Social Security and driver’s license numbers—the HIBP Houston City College card does not list SSNs or government ID numbers among compromised data types. Absence from the HIBP field list is not a guarantee those identifiers never appeared in every file, but BreachHistory will not invent them. If HCC or a state AG later publishes a notice that expands the categories, the catalog row should be updated.

Who is at risk

Current HCC students, recent graduates, and alumni whose email addresses appear in the dump. Family members who shared contact details on enrollment forms may also see phishing that name-drops Houston City College. Staff emails can appear in the same exports when directories are wide.

Because community colleges often serve working adults and first-generation students, attackers know password reuse is common across student email, banking, and employer SSO. Credential stuffing after an edtech dump is not theoretical—it is the default next step.

How this fits the 2026 edtech wave

June 2026 was a brutal month for U.S. higher education data. Glendale Community College landed on HIBP with ~794K emails after its own ShinyHunters disclosure. Moody Bible Institute and other institutions also appeared in the same HIBP window. The pattern is less “one exotic zero-day” and more industrial-scale theft of student information systems followed by public extortion branding.

For Texas readers, Houston City College is also a regional critical path: workforce certificates, dual-credit high school programs, and transfer pipelines into four-year universities. A dump that mixes citizenship status with academic history hits immigration-sensitive households especially hard.

Why alumni should still care

Community-college dumps age badly for victims because contact data stays useful for years. An email from 2019, a phone number used on a FAFSA worksheet, or a physical address from the last semester still power SIM-swap prep and account-recovery social engineering. Alumni who assume “I graduated, so I’m out of scope” are often wrong—HIBP’s Houston City College card explicitly includes alumni alongside current students.

If you ever used a personal Gmail/Outlook address with HCC, check that address even if you no longer have student email. Attackers prefer personal inboxes; they survive graduation.

Action items

  1. Check Have I Been Pwned for every email you used with HCC.
  2. Watch financial-aid and transcript phishing that references the breach, unpaid balances, or “secure document portals.”
  3. Change reused passwords on email, banking, and employer accounts if you recycled an HCC-related password.
  4. Enable MFA on student email and any remaining HCC portal access.
  5. Freeze credit if you later receive a college or AG notice that expands exposure to SSN or driver’s license data.
  6. Tell family members who co-signed or shared contact info—secondary phishing is common after education dumps.

Canonical record

Houston City College 2026 on BreachHistory — HIBP-verified 831,642 emails; ShinyHunters campaign context.

Sources: Have I Been Pwned, SecurityAffairs, Sherlock Forensics summary.

Updated 2026-08-05.