Glendale Community College is tied to a leak dataset containing 111,828 indexed records from a June 16, 2026 cybersecurity incident involving student educational records and exposed personal information (leaksear.ch metadata). The college said data related to student educational records was potentially copied without authorization, and Have I Been Pwned lists a related breach with 793.9k affected accounts added on July 11, 2026 (glendale.edu, haveibeenpwned.com).
What happened
Glendale Community College said it was notified about a potential cybersecurity incident on June 16, 2026, then isolated and secured its network and engaged third-party specialists to help contain and investigate the activity. The college said certain data related to student educational records was potentially copied without authorization and that it did not have reason to believe personally identifiable employee data had been compromised (glendale.edu).
Have I Been Pwned describes the breach as connected to a ShinyHunters pay-or-leak extortion campaign and says data allegedly obtained from Glendale was later published online. GCC's own public notice confirms potential unauthorized copying, but does not name an actor in the notice (haveibeenpwned.com, glendale.edu).
What data was exposed
The leaksear.ch indexed dataset includes searchable fields for address, date of birth, email, name, phone number, and username. Other record fields include city, first name, middle name, last name, school email, secondary email, login ID, student and faculty flags, Canvas status, postal code, state, account status markers, and source file metadata (leaksear.ch metadata).
Public notices say the potentially impacted information varies by person and may include names plus Social Security numbers, driver's license numbers, passport numbers, financial aid information, or health-related information. Have I Been Pwned lists compromised data categories including academic records, dates of birth, email addresses, genders, government-issued IDs, names, phone numbers, and physical addresses (oag.ca.gov, haveibeenpwned.com).
Why this matters
The combination of student contact data, dates of birth, usernames, and school-related identifiers can make phishing and account-recovery attempts more credible. The possible exposure of government identifiers, financial aid information, or health-related information also raises identity theft and fraud risk for affected individuals. GCC said it is offering complimentary credit monitoring and identity protection services, and advised potentially impacted people to review account statements, insurance statements, and credit history for unauthorized activity (glendale.edu).
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include address, date of birth, email, name, phone, and username.