McGraw Hill Data Breach 2026: 13.5 Million Records, a Misconfigured Salesforce Page, and the EdTech Pattern
Breach Summary
In April 2026, the 117-year-old education publisher McGraw Hill became the latest name on the ShinyHunters leak site, after the group published more than 100 gigabytes of data tied to 13.5 million accounts. The cause was not a sophisticated intrusion. It was a misconfigured webpage hosted in McGraw Hill's Salesforce environment, left accessible without proper authentication. The company described the exposure as a limited set of data from a webpage hosted by Salesforce on its platform. The data, names, physical addresses, phone numbers, and email addresses for millions of students, educators, and customers, was anything but limited once it was posted publicly.
What Happened
ShinyHunters listed McGraw Hill on its dark-web extortion portal in April 2026, claiming roughly 45 million Salesforce records and threatening to publish unless paid by April 14. McGraw Hill confirmed the incident to BleepingComputer, stating that attackers had exploited a misconfiguration in its Salesforce environment and that the exposure was limited to a webpage hosted on the platform, not its core systems, courseware, or customer databases.
When the extortion attempt did not produce a payment, the group released over 100 GB of data. Have I Been Pwned analysis confirmed 13.5 million unique email addresses across the leaked files, with names, phone numbers, and physical addresses appearing inconsistently across records. Roughly 47 percent of the email addresses had appeared in prior breaches, but a substantial share were newly exposed. No passwords or financial data were included. Salesforce stated there was no indication its platform had been compromised and that the event was not tied to any known vulnerability in its technology, pointing instead to customer-side misconfiguration.
Attack Vector Detail
This breach is a study in how cloud misconfiguration becomes mass exposure. A Salesforce-hosted webpage, intended to serve some subset of data, was configured to allow access without proper authentication controls. To an attacker, that is not a hack so much as an open door: the data was reachable by anyone who found the page. ShinyHunters has industrialized the discovery of exactly these misconfigurations across organizations that rely on Salesforce, which is why the same root cause has surfaced at multiple companies in the same window.
The contrast with a classic intrusion matters for how executives think about defense. There was no malware, no credential theft, no lateral movement to detect. The control that would have prevented this is mundane: correct access configuration on a public-facing cloud asset, verified by routine review. See our explainer on the supply chain attack and the discipline of the security audit.
Breach Pattern Timeline
- Early April 2026 — ShinyHunters breaches a misconfigured McGraw Hill Salesforce-hosted webpage.
- ~April 11-14, 2026 — Group lists McGraw Hill on its leak site, claims ~45M records, threatens release by April 14.
- April 2026 — Negotiations fail; 100+ GB published. HIBP confirms 13.5M unique email addresses.
- Pattern — Part of the 2026 EdTech breach wave (Instructure/Canvas, PowerSchool) and the broader ShinyHunters Salesforce campaign.
Executive Lessons
- Misconfiguration is the modern breach. No exploit was required. Public cloud assets need authentication by default and configuration review as a standing control, not a one-time setup task.
- The shared-responsibility line is where breaches live. Salesforce was not compromised; the customer's configuration was. Knowing exactly which security responsibilities are yours versus your platform's is essential, and most organizations assume the platform covers more than it does.
- 'Limited' does not survive contact with a 100 GB leak. The gap between the company's framing and the public dataset is the credibility cost. Disclosure should match reality.
- The pattern is the signal. McGraw Hill is one of many. This breach belongs to the campaign documented in our analysis of the 2026 extortion wave.
Private Equity Implications
For sponsors with EdTech, SaaS, or any customer-facing cloud business in the portfolio, McGraw Hill is a cheap lesson in an expensive risk. The breach required no advanced tradecraft; it required a single misconfigured public asset. That means the exposure is everywhere a portfolio company has shipped cloud-hosted pages quickly, which is to say nearly everywhere.
Diligence and hold-period monitoring should include external attack-surface review: what public cloud assets does the company expose, and are any of them serving data without authentication? It is one of the fastest, cheapest checks available and it maps directly to the way these breaches actually happen. See cyber due diligence.
How Cloudskope Can Help
Cloudskope runs external attack-surface and cloud-configuration reviews that catch exactly this failure mode: public assets exposing data without authentication, misconfigured SaaS pages, and the shared-responsibility gaps organizations assume their platform covers. For sponsors, we build this into diligence so a misconfiguration is found by us, not by an extortion group.
Frequently Asked Questions
Frequently asked questions
What caused the McGraw Hill data breach?
A misconfiguration in a McGraw Hill webpage hosted in its Salesforce environment left data accessible without proper authentication. ShinyHunters accessed and later leaked it.
How many people were affected?
Have I Been Pwned confirmed 13.5 million unique email addresses in the 100+ GB of leaked files, with names, phone numbers, and physical addresses appearing inconsistently.
Was Salesforce hacked?
No. Salesforce stated there was no indication its platform was compromised and the event was not tied to any known vulnerability; the issue was a customer-side misconfiguration.
Were passwords or financial data exposed?
No passwords or financial data were included in the leaked dataset, but the exposed contact details still enable phishing and social engineering.
Why does this matter beyond education?
The root cause, a misconfigured public cloud asset, applies to any organization running customer-facing cloud platforms.
.png)