Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposureunderground-data-leakbreach-disclosure-notificationthird-party-vendor-breach

McGraw Hill breach exposed 13.5 million accounts after Salesforce webpage misconfiguration

Updated 2mo agoFirst seen Apr 14, 20267 sources

McGraw Hill confirmed that attackers accessed a limited set of internal data through a misconfigured Salesforce-hosted webpage, after the ShinyHunters extortion group claimed responsibility and threatened to publish stolen information unless a ransom was paid. The company said the incident was tied to a broader issue affecting multiple organizations using Salesforce-hosted environments and maintained that its Salesforce accounts, customer databases, courseware, internal systems, Social Security numbers, financial account information, and student data from its educational platforms were not impacted.

After the extortion deadline passed, data tied to 13.5 million McGraw Hill user accounts was reportedly leaked publicly, with Have I Been Pwned saying the dump contained more than 100GB of files, including unique email addresses and some names, physical addresses, and phone numbers. The leak contradicted earlier company statements that the exposed data was limited and non-sensitive, while ShinyHunters separately claimed to hold 45 million Salesforce records; McGraw Hill said it secured the affected webpages, brought in external cybersecurity experts, and is working with Salesforce to strengthen protections.

Share:
McGraw Hill breach exposed 13.5 million accounts after Salesforce webpage misconfiguration
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 3, 20262mo ago

ShinyHunters lists Instructure Holdings as a victim

A RedPacket Security post reported that ShinyHunters had identified Instructure Holdings, Inc., associated with Canva LMS and instructure.com, as a ransomware/extortion victim. This represents a separate victim disclosure from the previously documented McGraw-Hill incident.

[SHINYHUNTERS] - Ransomware Victim: Instructure Holdings, Inc[.] (Canva LMS, instructure[.]com) - RedPacket Security
Apr 16, 20262mo ago

ShinyHunters leaks McGraw-Hill data affecting 13.5 million accounts

After the extortion threat, ShinyHunters publicly leaked more than 100GB of data tied to 13.5 million McGraw-Hill user accounts. Have I Been Pwned reported the exposed files contained 13.5 million unique email addresses along with some names, physical addresses, and phone numbers.

Apr 14, 20262mo ago

McGraw-Hill confirms limited data breach tied to Salesforce-hosted webpage

McGraw-Hill confirmed that attackers accessed a limited set of internal data through a misconfigured webpage hosted on Salesforce. The company said its Salesforce accounts, customer databases, courseware, internal systems, financial data, Social Security numbers, and student platform data were not affected, and that it secured the webpage and engaged external cybersecurity experts.

ShinyHunters claims McGraw-Hill breach and issues extortion threat

The ShinyHunters extortion group listed McGraw-Hill on its leak site, claiming it had stolen 45 million Salesforce records containing personally identifiable information. The group threatened to publish the data unless a ransom was paid, with publication set for April 14.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

35 LINKEDOpen in app
Threat actors
1 linked
Affected products
2 linked
CommvaultSkype For Business
Organizations
32 linked
SalesforceMcGraw-HillRockstar GamesBleepingComputerMatch GroupPanera BreadCarGurusWynn ResortsTelus DigitalInfinite CampusHims & HersArctic WolfHave I Been PwnedBlackpoint CyberSalesforceSnowflakeCommvaultEsetAnthropicZoho CorporationMicrosoft CorporationGitHubSoundcloudBitdefenderMatch GroupRockstar GamesPanera BreadFigureCanada GooseCanada GooseCorsica TechnologiesvpnMentor
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

McGraw Hill breach exposed 13.5 million accounts after Salesforce webpage misconfiguration | Mallory