Stacked textbooks and notebooks on a wooden desk
Photo via Unsplash

TL;DR: ShinyHunters breached McGraw-Hill through a Salesforce misconfiguration and leaked over 100GB of data: 13.5 million unique email addresses, plus names, phone numbers, and physical addresses. The education publisher refused to pay ransom before an April 14 deadline. ShinyHunters claims to hold 45 million records total. If you've ever used a McGraw-Hill product (and if you went to school in the US, you probably have) check Have I Been Pwned.

Another Salesforce Misconfiguration, Another Massive Leak

On April 16, 2026, ShinyHunters published McGraw-Hill's stolen data after the company missed a ransom deadline. The attack didn't target McGraw-Hill's core systems. It didn't need to. A misconfigured Salesforce environment gave the hackers everything they wanted.

McGraw-Hill's own statement is telling: the attackers accessed "a limited set of data from a webpage hosted by Salesforce on its platform." The company insists the breach "did not involve unauthorized access to McGraw Hill's Salesforce accounts, customer databases, courseware, or internal systems" [1]. Salesforce, for its part, says there's "no indication that the Salesforce platform has been compromised" [2].

Both companies pointing fingers at each other. Meanwhile, 13.5 million people's data is sitting on the open internet.

What's in the Leak

Troy Hunt added the breach to Have I Been Pwned on April 16 after verifying the data. Here's what's floating around:

  • 13.5 million unique email addresses across multiple database files
  • Names, phone numbers, and physical addresses (present inconsistently across records)
  • Over 100GB of data dumped publicly

McGraw-Hill says the stolen data is "limited in scope and consists of non-sensitive information": no Social Security numbers, no financial data, no student records [1].

That's a generous definition of "non-sensitive." Your full name, email, phone number, and home address is enough for identity theft, targeted phishing, and social engineering. Ask the people who got scammed after the Harvard and UPenn breach how "non-sensitive" that data felt.

Here's the kicker: 47% of the exposed email addresses had already appeared in previous breach databases [3]. These aren't fresh targets. They're people whose data has been circulating for years, and now there's another layer of personal information attached to it.

ShinyHunters' Salesforce Blitz

McGraw-Hill isn't an isolated hit. ShinyHunters has been systematically exploiting Salesforce misconfigurations across dozens of companies. The pattern is the same every time: find a misconfigured integration, extract data through legitimate API access, demand ransom, dump everything when the company doesn't pay.

Their recent Salesforce-linked victims include:

TransUnion

Credit bureau breached via Salesforce supply chain. Millions of consumer credit records exposed. Full coverage.

Hims & Hers

Telehealth company breached through Zendesk and Okta integrations. Patient data exposed. Full coverage.

100+ Companies

ShinyHunters' SSO campaign targeting Okta-connected organizations hit triple digits. Full coverage.

ShinyHunters claims to hold 45 million Salesforce records from McGraw-Hill alone, more than three times what they've already published [4]. That's either a bluff to pressure future victims, or there's a lot more data coming.

How Salesforce Misconfigurations Happen

Most Salesforce breaches don't exploit bugs in Salesforce itself. They exploit how companies set it up. The usual suspects:

  • Over-permissioned API integrations: third-party apps that can read way more data than they need
  • Exposed community portals: guest users with access to internal data objects
  • Stolen OAuth tokens: legitimate-looking access that bypasses login controls
  • Misconfigured sharing rules: records visible to anyone with a valid session

McGraw-Hill described the breach vector as "a webpage hosted by Salesforce." That sounds a lot like an exposed Salesforce Community or Experience Cloud page, a portal that was supposed to be restricted but wasn't locked down properly.

Salesforce's response, "no indication that the Salesforce platform has been compromised," is technically true and completely unhelpful. The platform is fine. The way thousands of companies configure it is not. And ShinyHunters knows exactly where to look.

Why This Matters for Students and Parents

McGraw-Hill isn't just another tech company. They publish textbooks used in virtually every American school and university. Their digital platforms (Connect, ALEKS, SIMnet) are mandatory for millions of students every semester.

If you've taken a college course in the last decade, there's a good chance your email address is in this leak. If your kid uses McGraw-Hill's online homework tools, their email might be too.

The company says no student data was compromised. But "student data" has a specific legal meaning under FERPA. Email addresses and phone numbers of people who happen to be students? That's a gray area McGraw-Hill is clearly trying to stay on the right side of.

What to Do Right Now

Check Have I Been Pwned

Go to haveibeenpwned.com and search your email. The McGraw-Hill breach has been added.

Watch for Phishing

Scammers now have your name, email, and possibly your school affiliation. Be skeptical of any email claiming to be from McGraw-Hill, your school, or a "breach notification service."

Lock Down Your Accounts

If you use the same email/password combination on McGraw-Hill as other sites, change those passwords now. Use a password manager.

Monitor for Identity Theft

With name + email + phone + address, attackers have enough for SIM swapping, targeted phishing, or account takeover. Consider a credit freeze if your physical address was exposed.

The Salesforce Problem Isn't Going Away

ShinyHunters has found a goldmine. Salesforce is everywhere. 150,000+ companies use it. Most of them configured their instances years ago and never looked back. The misconfigurations ShinyHunters exploits aren't exotic. They're mundane: a community page that should've been locked, an API token that should've been scoped, a sharing rule that should've been restricted.

McGraw-Hill is the latest victim. They won't be the last. If your company uses Salesforce, audit your configuration now. Check your community access controls, review API permissions, and run Salesforce's built-in Health Check tool. Because ShinyHunters is checking your configuration whether you are or not.

References

  1. The Record - Educational company McGraw Hill says Salesforce misconfiguration led to data leak (April 2026)
  2. Security Magazine - McGraw Hill Data Breach Caused by Salesforce Misconfiguration (April 2026)
  3. Cyber Insider - McGraw Hill data breach incident exposed 13.5 million accounts (April 2026)
  4. The Register - McGraw Hill linked to 13.5M-record data leak (April 16, 2026)
  5. Have I Been Pwned - McGraw Hill breach entry
  6. Bleeping Computer - Data breach at edtech giant McGraw Hill affects 13.5 million accounts (April 2026)