01Summary
In early April 2026, ShinyHunters added McGraw Hill to their leak site claiming theft of 13.5 million records. The company confirmed the incident on April 14, stating unauthorized access to certain systems had occurred. Exposed data included names, email addresses, and other contact information. The breach was part of ShinyHunters' broader campaign targeting Salesforce instances and education sector organizations.
02Background
McGraw Hill is a major educational publishing and learning technology company. Its platforms contain sensitive student, educator, and customer data.
03Key revelations
- 01Ongoing risks in Salesforce ecosystems.
- 02Education sector remains a prime target.
04Technical analysis
The breach was linked to Salesforce platform access issues common in ShinyHunters' 2025-2026 campaign (often via vishing or OAuth abuse).
- Attack vector
- Salesforce compromise / Misconfiguration
- Attack method
- Data exfiltration and extortion
- Initial access
- Compromised credentials / Third-party integration
- Exfiltration
- Bulk data extraction
Vulnerabilities exploited
- Salesforce access control issues
05Threat actor
ShinyHunters is a prolific cybercriminal extortion group known for targeting large datasets via SaaS platforms.
Aliases
- SH
Attribution sources
- ShinyHunters leak site
- BleepingComputer
- McGraw Hill statements
06Victims and impact
Countries affected
- Global
07Data exposed
Data types
- PII
- Email addresses
- Contact information
- Educational records
08Financial damage
Extortion pressure; potential regulatory fines and class-action lawsuits.
09Timeline
- 2026-04-01Initial compromise claimed.
- 2026-04-14McGraw Hill publicly confirms breach.
10Reaction and fallout
Public reaction
Concern from schools and educators about student data privacy.
11Legal
Ongoing investigations and potential lawsuits.
Civil lawsuits
- Anticipated class-action lawsuits
12Aftermath
Security improvements
- Enhanced Salesforce security controls
13Significance and legacy
Significance
Part of ShinyHunters' large-scale education and SaaS campaign in 2026.
Legacy
Further highlighted third-party SaaS risks in education.
14Disclosure and media
- Authentication
- ShinyHunters leak site
Publishing organisations
- BleepingComputer
- Cybernews
15Field notes
- 01Part of a wider ShinyHunters campaign affecting multiple education companies.
16Resolution
McGraw Hill confirmed the breach and worked to contain it; data not publicly leaked after extortion process.
17Sources
Official documents
- McGraw Hill security notice
References
- [1]BleepingComputer reports
- [2]McGraw Hill statements









