McGraw Hill Confirms Data Exposure Linked to Salesforce Misconfiguration

Share
An open book and a cloud with an unlocked padlock on a yellow background, symbolizing the McGraw Hill breach.

The education publishing giant is the latest victim of a widespread cloud configuration issue, with Have I Been Pwned independently verifying 13.5 million unique email addresses in data leaked by ShinyHunters, which publicly claimed responsibility.

NEW YORK, NY — McGraw Hill, one of the world’s "Big Three" educational publishers, has confirmed a data security incident traced to a misconfigured Salesforce-hosted webpage. The breach, which surfaced in mid-April 2026, exposed names and email addresses, along with phone numbers and mailing addresses in some records. The extortion group ShinyHunters publicly claimed responsibility, and the breach notification service Have I Been Pwned has since independently verified 13.5 million unique email addresses in the leaked files.

Update (August 26, 2026): ShinyHunters initially claimed on its leak site to hold 45 million Salesforce records and set an April 14, 2026 deadline; the ransom amount was never disclosed. McGraw Hill did not pay, and the group subsequently released more than 100 GB of data. Have I Been Pwned then independently verified 13.5 million unique email addresses in the leaked files, alongside names and — inconsistently — phone numbers and mailing addresses. McGraw Hill says Social Security numbers, financial and payment data, student academic records, and courseware or platform data were not exposed, and that the root cause was a misconfiguration in a Salesforce-hosted webpage that "appears to be part of a broader issue" affecting multiple organizations rather than a compromise of its own systems.

The incident was first brought to light after ShinyHunters, the same extortion crew behind the ADT data breach, began circulating samples of the data on hacking forums and publicly claimed responsibility, saying it had exploited a misconfiguration in a Salesforce-hosted webpage.

Impact Metric Details
Threat Actor ShinyHunters (publicly claimed responsibility)
Verified Records 13.5 million unique email addresses verified by Have I Been Pwned (45 million records initially claimed)
Root Cause Misconfigured Salesforce-hosted webpage
Exposed Data Names, email addresses, and — inconsistently — phone numbers and mailing addresses
Not Exposed Social Security numbers, financial/payment data, student academic records, courseware and platform data

The Salesforce Misconfiguration Crisis

McGraw Hill said the misconfiguration "appears to be part of a broader issue" affecting multiple organizations, rather than a compromise of its own systems. The underlying pattern is systemic: Salesforce-hosted pages and communities are inadvertently left accessible to the public internet, allowing attackers to query sensitive objects — such as user lists — without requiring authentication.

According to reports from The Register and BleepingComputer, ShinyHunters issued an extortion threat to the publisher before leaking the data. McGraw Hill says Social Security numbers, financial and payment data, student academic records, and courseware data were not exposed — but the sheer volume of personal data leaked provides a goldmine for secondary phishing attacks targeting students and educators.

EdTech in the Crosshairs

This breach follows a pattern of high-volume attacks against the education sector. With millions of students transitioning to digital learning platforms, EdTech providers have become high-value targets for data harvesters. The McGraw Hill leak has already been indexed by the data breach notification service Have I Been Pwned, allowing affected users to check whether their address was among the 13.5 million unique email addresses the service verified in the leaked files.


The CyberSignal Analysis

Signal 01 — The "Silent" Cloud Leak

Unlike a ransomware attack that locks systems, a misconfiguration leak is "silent." The data is simply there for anyone who knows how to look. McGraw Hill’s experience serves as a critical warning for organizations using Salesforce or similar CRM platforms: standard security audits often miss "ghost" permissions in public-facing communities. If your Salesforce instance hasn't been audited specifically for guest user permissions in the last 90 days, it is likely at risk.

Signal 02 — Trust Decay in Education

For EdTech companies, the primary product isn't the textbook — it’s the student data. When 13.5 million unique email addresses are exposed, the resulting "trust decay" can lead to significant friction with school districts and universities. Names paired with email addresses — and, in some records, phone numbers and mailing addresses — are enough to build convincing McGraw Hill-branded lures, so expect "Phishing-as-a-Service" operators to work the leaked list using "account reset" or "grade update" themes.


Sources

Type Source
News Alert The Register: McGraw Hill Salesforce Leak
Technical Intel BleepingComputer: Extortion Threat Details
Verification HIBP: McGraw Hill Breach Indexed
Follow-Up BleepingComputer: Breach Affects 13.5 Million Accounts
Analysis The Record: Leak Tied to Salesforce Misconfiguration