Investigation · Student Records

Glendale Community College Data Breach Investigation

Hall Attorneys is evaluating potential claims for students affected by a June 2026 Glendale Community College incident involving educational records and sensitive identity information.

Verified indexed count
793,925

unique email addresses listed by HIBP

Reported event
June 16, 2026

date GCC says it was notified

Official scope
Students

GCC says educational records were potentially copied

Answer at a glance

What happened in the Glendale Community College data breach?

Glendale Community College says it was notified of a potential cybersecurity incident on June 16, 2026, isolated and secured its network, and engaged third-party specialists.

GCC says certain data related to student educational records was potentially copied without authorization. Have I Been Pwned separately says data was later published online in a ShinyHunters pay-or-leak campaign and lists 793,925 unique email addresses.

The official notice and the HIBP entry describe overlapping but not identical data categories. The information involved for any particular person must be determined from that person's notice and other reliable records.

This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.

  1. Date assigned to the indexed breach

    Have I Been Pwned assigns June 15 as the breach date for its verified Glendale Community College dataset entry.

  2. College notified and responds

    GCC says it learned of the incident, secured its network, and engaged third-party specialists to contain and investigate the activity.

  3. California notice submitted

    The California Attorney General lists GCC's breach notification, which describes potentially copied student records and an offer of complimentary monitoring and identity protection.

  4. Breach added to Have I Been Pwned

    HIBP added a verified entry listing 793,925 unique email addresses and eight compromised data categories.

Reported data categories

What information was involved?

GCC's notice and the HIBP dataset entry provide different views of the incident. Both should be read carefully because no source establishes that every category applied to every student.

Important distinction

GCC says a person's potentially affected data may include only one or all listed types. GCC also says it did not have reason to believe personally identifiable employee data was compromised.

GCC notice — identity
Name, Social Security number, driver's license number, or passport number
GCC notice — student data
Financial-aid information or health-related information
HIBP — account and profile
Email addresses, dates of birth, genders, names, phone numbers, and physical addresses
HIBP — education and IDs
Academic records and government-issued IDs

Who may want to contact us

Students and notice recipients

GCC's current public statement focuses on student educational records. The investigation is therefore centered on current and former students, including people who received notice or monitoring.

Current or former GCC students who received an incident notice

Students whose email address appears in the HIBP breach entry

People whose educational, financial-aid, health, Social Security, driver's-license, or passport information may have been involved

People experiencing GCC-themed phishing, identity misuse, fraud, monitoring costs, or lost time

What to preserve

Keep notices, student records, and monitoring documentation

Preserve relevant records, but do not send passwords, monitoring enrollment codes, full account numbers, government identification, or unredacted credit reports through ordinary website forms.

Notices and monitoring offers

Keep the complete Glendale Community College notice, envelope, email, enrollment instructions, deadline, and any later updates.

Relationship records

Preserve records showing your student or alumni relationship with GCC, including dated account, enrollment, employment, alumni, transaction, or correspondence records.

Information held about you

Save records or dated screenshots showing the contact, identity, academic, employment, financial, or profile information the organization held about you.

Suspicious communications

Keep phishing emails, texts, calls, password-reset messages, account alerts, or other communications that use organization-specific details.

Credit and account records

Preserve credit alerts, unfamiliar-account notices, fraud reports, freeze confirmations, monitoring results, and relevant financial correspondence.

Time, expenses, and harm

Track time spent securing accounts or responding to misuse, along with out-of-pocket costs, lost funds, denied credit, or other concrete effects.

Investigation focus

Issues under review

Hall Attorneys is reviewing the reported access and publication, the data involved, GCC's notice and monitoring response, and harms reported by affected students.

  1. How GCC systems were accessed and when unauthorized copying began and ended
  2. Which student-record systems and historical records were involved
  3. How many distinct students were affected and why the indexed count is far larger than current enrollment
  4. How the categories in GCC's notice relate to the categories in the HIBP dataset
  5. Whether notice and offered monitoring were timely, complete, and available to every affected person
  6. Whether affected students experienced targeted phishing, identity theft, fraud, financial loss, monitoring costs, or time loss

Public records reviewed

Sources for the Glendale Community College incident

The sources below distinguish GCC's own notice from HIBP's indexed dataset description and broader technical campaign reporting.

Glendale Community College ·

Cyber Security Update

GCC's public description of the incident, student-record scope, response measures, data categories, and monitoring offer.

Read source: Cyber Security Update

California Attorney General ·

Submitted Breach Notification Sample

Publishes GCC's breach notification and links to the notice provided for potentially affected individuals.

Read source: Submitted Breach Notification Sample

Contact the firm

Did you receive a Glendale Community College breach notice?

Contact Hall Attorneys with your general relationship to GCC, whether you received notice or monitoring, and a summary of suspicious activity or loss. Do not include passwords, monitoring codes, Social Security numbers, or identification documents in an initial message.

Contact Hall Attorneys

Frequently asked questions

Glendale Community College breach FAQ

Is this a filed Glendale Community College data breach lawsuit?

No. This page describes an investigation by Hall Attorneys and does not state that the firm has filed a lawsuit concerning GCC.

How many Glendale Community College accounts were affected?

Have I Been Pwned lists 793,925 unique email addresses. That figure does not necessarily equal the number of distinct people.

What did GCC say was involved?

GCC says student educational records were potentially copied. Depending on the individual, its notice lists a name and one or more of a Social Security number, driver's license number, passport number, financial-aid information, or health-related information.

Were employee records involved?

GCC's current public update says it does not have reason to believe personally identifiable employee data was compromised. That statement concerns this 2026 incident and may be updated as the investigation develops.

What protection did GCC offer?

GCC says it offered potentially affected individuals complimentary credit monitoring and identity-protection services. Recipients should follow the enrollment instructions and deadline in their own notice.

Attorney Advertising

Hall Attorneys is not affiliated with Glendale Community College or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.