TL;DR: ShinyHunters breached McGraw-Hill through a Salesforce misconfiguration and leaked over 100GB of data: 13.5 million unique email addresses, plus names, phone numbers, and physical addresses. The education publisher refused to pay ransom before an April 14 deadline. ShinyHunters claims to hold 45 million records total. If you've ever used a McGraw-Hill product (and if you went to school in the US, you probably have) check Have I Been Pwned.
Another Salesforce Misconfiguration, Another Massive Leak
On April 16, 2026, ShinyHunters published McGraw-Hill's stolen data after the company missed a ransom deadline. The attack didn't target McGraw-Hill's core systems. It didn't need to. A misconfigured Salesforce environment gave the hackers everything they wanted.
McGraw-Hill's own statement is telling: the attackers accessed "a limited set of data from a webpage hosted by Salesforce on its platform." The company insists the breach "did not involve unauthorized access to McGraw Hill's Salesforce accounts, customer databases, courseware, or internal systems" [1]. Salesforce, for its part, says there's "no indication that the Salesforce platform has been compromised" [2].
Both companies pointing fingers at each other. Meanwhile, 13.5 million people's data is sitting on the open internet.
What's in the Leak
Troy Hunt added the breach to Have I Been Pwned on April 16 after verifying the data. Here's what's floating around:
- 13.5 million unique email addresses across multiple database files
- Names, phone numbers, and physical addresses (present inconsistently across records)
- Over 100GB of data dumped publicly
McGraw-Hill says the stolen data is "limited in scope and consists of non-sensitive information": no Social Security numbers, no financial data, no student records [1].
That's a generous definition of "non-sensitive." Your full name, email, phone number, and home address is enough for identity theft, targeted phishing, and social engineering. Ask the people who got scammed after the Harvard and UPenn breach how "non-sensitive" that data felt.
Here's the kicker: 47% of the exposed email addresses had already appeared in previous breach databases [3]. These aren't fresh targets. They're people whose data has been circulating for years, and now there's another layer of personal information attached to it.
ShinyHunters' Salesforce Blitz
McGraw-Hill isn't an isolated hit. ShinyHunters has been systematically exploiting Salesforce misconfigurations across dozens of companies. The pattern is the same every time: find a misconfigured integration, extract data through legitimate API access, demand ransom, dump everything when the company doesn't pay.
Their recent Salesforce-linked victims include:
TransUnion
Credit bureau breached via Salesforce supply chain. Millions of consumer credit records exposed. Full coverage.
Hims & Hers
Telehealth company breached through Zendesk and Okta integrations. Patient data exposed. Full coverage.
100+ Companies
ShinyHunters' SSO campaign targeting Okta-connected organizations hit triple digits. Full coverage.
ShinyHunters claims to hold 45 million Salesforce records from McGraw-Hill alone, more than three times what they've already published [4]. That's either a bluff to pressure future victims, or there's a lot more data coming.
How Salesforce Misconfigurations Happen
Most Salesforce breaches don't exploit bugs in Salesforce itself. They exploit how companies set it up. The usual suspects:
- Over-permissioned API integrations: third-party apps that can read way more data than they need
- Exposed community portals: guest users with access to internal data objects
- Stolen OAuth tokens: legitimate-looking access that bypasses login controls
- Misconfigured sharing rules: records visible to anyone with a valid session
McGraw-Hill described the breach vector as "a webpage hosted by Salesforce." That sounds a lot like an exposed Salesforce Community or Experience Cloud page, a portal that was supposed to be restricted but wasn't locked down properly.
Salesforce's response, "no indication that the Salesforce platform has been compromised," is technically true and completely unhelpful. The platform is fine. The way thousands of companies configure it is not. And ShinyHunters knows exactly where to look.
Why This Matters for Students and Parents
McGraw-Hill isn't just another tech company. They publish textbooks used in virtually every American school and university. Their digital platforms (Connect, ALEKS, SIMnet) are mandatory for millions of students every semester.
If you've taken a college course in the last decade, there's a good chance your email address is in this leak. If your kid uses McGraw-Hill's online homework tools, their email might be too.
The company says no student data was compromised. But "student data" has a specific legal meaning under FERPA. Email addresses and phone numbers of people who happen to be students? That's a gray area McGraw-Hill is clearly trying to stay on the right side of.
What to Do Right Now
Check Have I Been Pwned
Go to haveibeenpwned.com and search your email. The McGraw-Hill breach has been added.
Watch for Phishing
Scammers now have your name, email, and possibly your school affiliation. Be skeptical of any email claiming to be from McGraw-Hill, your school, or a "breach notification service."
Lock Down Your Accounts
If you use the same email/password combination on McGraw-Hill as other sites, change those passwords now. Use a password manager.
Monitor for Identity Theft
With name + email + phone + address, attackers have enough for SIM swapping, targeted phishing, or account takeover. Consider a credit freeze if your physical address was exposed.
The Salesforce Problem Isn't Going Away
ShinyHunters has found a goldmine. Salesforce is everywhere. 150,000+ companies use it. Most of them configured their instances years ago and never looked back. The misconfigurations ShinyHunters exploits aren't exotic. They're mundane: a community page that should've been locked, an API token that should've been scoped, a sharing rule that should've been restricted.
McGraw-Hill is the latest victim. They won't be the last. If your company uses Salesforce, audit your configuration now. Check your community access controls, review API permissions, and run Salesforce's built-in Health Check tool. Because ShinyHunters is checking your configuration whether you are or not.
References
- The Record - Educational company McGraw Hill says Salesforce misconfiguration led to data leak (April 2026)
- Security Magazine - McGraw Hill Data Breach Caused by Salesforce Misconfiguration (April 2026)
- Cyber Insider - McGraw Hill data breach incident exposed 13.5 million accounts (April 2026)
- The Register - McGraw Hill linked to 13.5M-record data leak (April 16, 2026)
- Have I Been Pwned - McGraw Hill breach entry
- Bleeping Computer - Data breach at edtech giant McGraw Hill affects 13.5 million accounts (April 2026)