Inside the Qampus+ LMS Breach: How a Database Hack Exposed 9,782 Nigerian Students
HEROIC analysts found evidence of a database breach affecting Qampus+ LMS, a cloud-based Learning Management System serving educational institutions primarily in Nigeria. The breach was identified on March 12, 2025, and involved the exposure of 9,782 user records. The compromised data included email addresses, full names, birthdates, and phone numbers belonging to students, faculty, and staff connected to the platform. No passwords were included in the exposed dataset, but the personal information alone carries significant risk for the people affected.
Why Exposing Student and Staff Data Is So Harmful
Educational platforms hold some of the most personal data imaginable. Birthdates, full names, phone numbers, and institutional email addresses create a complete profile that attackers can use for social engineering. A threat actor armed with a student's name, birthday, and phone number can craft a convincing phishing message, impersonate a school administrator, or attempt to gain access to other services that use birthday-based identity verificaton. For younger users who may not yet recognise these tactics, the risk is particularly serious. Even without passwords in the dataset, the combination of identifiers is more than enough to cause real harm.
What Was Exposed in the Qampus+ LMS Breach
- Email Address
- First Name
- Last Name
- Birthday
- Phone Number
Why This Matters for Students, Faculty, and Schools
When personal data from educational platforms leaks, the consequences extend beyond the individuals directly affected. Stolen contact details are frequently used to launch phishing campains targeting entire school communities. Attackers may pose as IT support, financial aid offices, or school administrators to extract further sensitive information. Birthdates combined with full names can also enable identity theft, allowing criminals to open fraudulent accounts or apply for credit in a victim's name. Educational institutions that fail to protect this data also risk regulatory consequences and a loss of trust from the communities they serve.
How a Database Breach Targeting an LMS Works
Learning Management Systems store large volumes of personal data about their users, making them attractive targets. A database breach typically occurs when an attacker exploits a vulnerability in the platform's web application, uses stolen administrative credentials, or takes advantage of a misconfigured cloud storage setting to gain access to the backend database. Once inside, they can extract entire user tables in a matter of minutes. Cloud-based LMS providers serving multiple institutions can become single points of failure: one successful intrusion yields records from every school using the platform. The breached data is then compiled and distributed or sold on underground forums, where it is used in phishing, identity theft, and targeted fraud campaigns.
Check If Your Information Was Exposed
HEROIC's free breach scanner searches across more than 400 billion compromised records, including educational platform breaches like the Qampus+ LMS incident. If your email address or personal details appeared in this dataset, you should be on guard for phishing messages and unsolicited contact from unknown parties. Run a free check at HEROIC.com to find out whether your data has been compromised in this or any other known breach.
Breach Breakdown
9,782 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds