Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

hccs.edu

hccs.edu

Discovered 2026-06-15 14:24 UTC
Est. attack date 2026-06-15
Country US

Description:

Hundreds of thousands of student records containing full name, home address, phone, email, date of birth, gender, ethnicity, enrollment status, GPA, major, and student ID across all campuses. Daily and full student roster exports library credentials, PINs, and @student[.hccs[.edu accounts. Over 12,000 financial aid and bursar reports including FAFSA/ISIR suspense data with names, birthdates, emails, phones, and home addresses. Class rosters with birthdates, grades, academic programs, and contact information for tens of thousands of enrolled students per term. Over 344,000 international student documents including SEVIS I-20 forms, visa applications, passports, bank statements, tax returns, immigration affidavits, and acceptance letters. Over 14,000 student immunization and vaccination records including meningitis compliance documentation. Over 15,000 additional health and immunization documents across report archives and A LOT more was compromised. This is a final warning to reach out by 18 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 16 June 2026 | Warning: FINAL WARNING PAY OR LEAK

Infostealer activity detected by HudsonRock

Compromised Employees: 256

Compromised Users: 3648

Third Party Employee Credentials: 1228


External Attack Surface: 129


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mx1.hc2685-79.iphmx.com. Cisco/IronPort
TXT Records
  • iEcc0jG/Z4hiLddzx22IJICDp+Fk8usupvRrN3QRGhSh4nPO/zqEeWx0N35JLN2wHKhKvZvyS4yjR9nk/D+KFg==
  • ywykp0d5fy4q6plpxy5cd9tn9wq2cght
  • google-site-verification=Om1Fz9boNqBM2Z8nM2U92rf5YRYSZUsCKfiui3CYdh8
  • adobe-sign-verification=545032678db52adac77855971d12d1ef
  • v=spf1 ip4:198.64.7.113 ip4:209.235.202.39 ip4:107.20.210.250 ip4:52.1.14.157 exists:%{i}.spf.hc2685-79.iphmx.com include:spf.protection.outlook.com include:_netblocks.eloqua.com include:cust-spf.cashnet.com ~all
  • cisco-ci-domain-verification=f8b75a9385272a57cdfcc6ae8c5d7f33716cbd1a944f4aa6aba3ae697996f08
  • google-site-verification=Or8jDxhSkzllnzkfHmrcPfSNVgpW38OfLCGRlo5N4tk
  • rpcfosnl47tbl0lftqcdfu0k3i
  • duo_sso_verification=gTPhUe4ToDCIaSKshEYWd9tlfiuILsez7uvZYQqyP5QMxL1L7I9pW4y6j4YKkfDi
  • adobe-idp-site-verification=6d3d15d6-871a-4880-bee3-51d3fcb83667
  • workplace-domain-verification=5nvpmYZVRESVaDnWoiRFbH8sqpgxAw
  • have-i-been-pwned-verification=e85073fc549d93bea858b4c20d186788
  • ZOOM_verify_8lx33jFFQcSfDL6DM5o-Kg
Cloud / SaaS Services Detected
Adobe Cisco Cisco Duo Have I Been Pwned Zoom