Skip to content
Cyber Security Firms
ConfirmedEducation

Houston City College Data Breach (July 2026)

Houston City College had data on roughly 832,000 current students and alumni published after a June 2026 extortion campaign, exposing names, dates of birth, contact details, citizenship statuses and academic records, per the Have I Been Pwned listing.

Disclosed Updated
Organization
Houston City College
Sector
Education
Country
United States, TX
Incident date
June 16, 2026
Disclosed
July 28, 2026
Records affected
832,000
Attack type
Undisclosed
Threat actor
ShinyHunters
Status
Confirmed
Data exposed
  • Academic records
  • Citizenship statuses
  • Dates of birth
  • Email addresses
  • Genders
  • Names
  • Phone numbers
  • Physical addresses
Timeline
  1. Date of the breach recorded on the Have I Been Pwned listing.
  2. Have I Been Pwned loads the verified records, 831,642 accounts in total.
  3. Cyber Security News reports the stolen data was published on underground forums after the college did not meet the extortion demand.

What Happened

Per the Have I Been Pwned entry, Houston City College was the target of a ShinyHunters pay or leak extortion campaign in June 2026, and data taken from the college was later published publicly. The listing records 832,000 unique email addresses alongside names, addresses, phone numbers, academic records and other personal information relating to both current students and alumni. Have I Been Pwned loaded 831,642 accounts on July 28, 2026.

Cyber Security News reported on July 29, 2026 that the exposed dataset covered student names, email addresses, phone numbers, physical addresses, dates of birth, gender information and citizenship status, along with academic records. According to that report, the attackers downloaded a significant dataset from the college's systems and later posted it on underground forums, which the publication says put the files in front of a wider set of criminal buyers.

Neither source states how the attackers first reached the college's systems. The Cyber Security News report notes only that access was gained and a dataset was taken, and it does not identify the entry point. Neither source carries a statement from Houston City College about the incident, and neither describes which internal systems held the records or how far back the student and alumni data runs.

What Was Exposed

8 classes of data across 831,642 records, per Have I Been Pwned: Houston City College, 831,642 breached accounts: academic records, citizenship statuses, dates of birth, email addresses, genders, names, phone numbers and physical addresses.

Names, dates of birth, home addresses and citizenship statuses in one file are enough to open credit in a student's name or to impersonate the college convincingly in a message about enrollment or financial aid.

What to Do If You Are Affected

The full sequence, and what to do in what order, is in what to do after a data breach.

What Is Not Known Yet

Houston City College has not published a statement about the incident, and no source says how the attackers reached its systems. Nobody has said whether affected students and alumni are being notified individually or offered credit monitoring.

Sources

  1. Have I Been Pwned: Houston City College, 831,642 breached accounts
  2. Cyber Security News: Houston City College Data Breach Exposes 832k Unique Student Email Addresses, July 29, 2026
On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →