McGraw Hill Confirms Data Exposure Linked to Salesforce Misconfiguration
The education publishing giant is the latest victim of a widespread cloud configuration issue, with Have I Been Pwned independently verifying 13.5 million unique email addresses in data leaked by ShinyHunters, which publicly claimed responsibility.
NEW YORK, NY — McGraw Hill, one of the world’s "Big Three" educational publishers, has confirmed a data security incident traced to a misconfigured Salesforce-hosted webpage. The breach, which surfaced in mid-April 2026, exposed names and email addresses, along with phone numbers and mailing addresses in some records. The extortion group ShinyHunters publicly claimed responsibility, and the breach notification service Have I Been Pwned has since independently verified 13.5 million unique email addresses in the leaked files.
Update (August 26, 2026): ShinyHunters initially claimed on its leak site to hold 45 million Salesforce records and set an April 14, 2026 deadline; the ransom amount was never disclosed. McGraw Hill did not pay, and the group subsequently released more than 100 GB of data. Have I Been Pwned then independently verified 13.5 million unique email addresses in the leaked files, alongside names and — inconsistently — phone numbers and mailing addresses. McGraw Hill says Social Security numbers, financial and payment data, student academic records, and courseware or platform data were not exposed, and that the root cause was a misconfiguration in a Salesforce-hosted webpage that "appears to be part of a broader issue" affecting multiple organizations rather than a compromise of its own systems.
The incident was first brought to light after ShinyHunters, the same extortion crew behind the ADT data breach, began circulating samples of the data on hacking forums and publicly claimed responsibility, saying it had exploited a misconfiguration in a Salesforce-hosted webpage.
The Salesforce Misconfiguration Crisis
McGraw Hill said the misconfiguration "appears to be part of a broader issue" affecting multiple organizations, rather than a compromise of its own systems. The underlying pattern is systemic: Salesforce-hosted pages and communities are inadvertently left accessible to the public internet, allowing attackers to query sensitive objects — such as user lists — without requiring authentication.
According to reports from The Register and BleepingComputer, ShinyHunters issued an extortion threat to the publisher before leaking the data. McGraw Hill says Social Security numbers, financial and payment data, student academic records, and courseware data were not exposed — but the sheer volume of personal data leaked provides a goldmine for secondary phishing attacks targeting students and educators.
EdTech in the Crosshairs
This breach follows a pattern of high-volume attacks against the education sector. With millions of students transitioning to digital learning platforms, EdTech providers have become high-value targets for data harvesters. The McGraw Hill leak has already been indexed by the data breach notification service Have I Been Pwned, allowing affected users to check whether their address was among the 13.5 million unique email addresses the service verified in the leaked files.
The CyberSignal Analysis
Signal 01 — The "Silent" Cloud Leak
Unlike a ransomware attack that locks systems, a misconfiguration leak is "silent." The data is simply there for anyone who knows how to look. McGraw Hill’s experience serves as a critical warning for organizations using Salesforce or similar CRM platforms: standard security audits often miss "ghost" permissions in public-facing communities. If your Salesforce instance hasn't been audited specifically for guest user permissions in the last 90 days, it is likely at risk.
Signal 02 — Trust Decay in Education
For EdTech companies, the primary product isn't the textbook — it’s the student data. When 13.5 million unique email addresses are exposed, the resulting "trust decay" can lead to significant friction with school districts and universities. Names paired with email addresses — and, in some records, phone numbers and mailing addresses — are enough to build convincing McGraw Hill-branded lures, so expect "Phishing-as-a-Service" operators to work the leaked list using "account reset" or "grade update" themes.