2026 McGraw Hill — Salesforce misconfiguration; 13.5M emails (HIBP)
Data compromised
Names, emails, phones, some addresses per press analyses—no SSNs/student records per company statement
Technical writeup
In mid-April 2026, McGraw Hill confirmed to reporters that data had appeared online after extortion activity attributed to ShinyHunters, which listed the company on a leak site with a short-fuse deadline. Trade reporting (e.g., The Register) described a misconfiguration affecting a Salesforce-hosted web property—framed by journalists as part of a broader Salesforce-side issue affecting multiple organizations—and cited on the order of ~13.05 million unique email addresses and more than 100 GB of material in public analyses. McGraw Hill’s public statements emphasized that the situation did not reflect unauthorized access to its Salesforce customer databases, courseware, or core internal systems, and that categories such as SSNs, financial accounts, and student educational records from platforms were not involved in the manner described by the company. Independent researchers and outlets published varying figures; treat precise volumes as subject to ongoing reconciliation.
Root cause
Salesforce-hosted web exposure / misconfiguration (per company and press); extortion follow-on
References
- https://www.theregister.com/2026/04/16/mcgraw_hill_salesforce/
- https://cyberinsider.com/mcgraw-hill-data-breach-incident-exposed-13-5-million-accounts/
- https://www.bleepingcomputer.com/news/security/mcgraw-hill-confirms-data-breach-following-extortion-threat/
- https://www.securitymagazine.com/articles/102233-mcgraw-hill-data-breach-caused-by-salesforce-misconfiguration
- https://haveibeenpwned.com/Breach/McGrawHill
- https://www.pkware.com/blog/2026-data-breaches