EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-mcgraw-hill-breach
044/430

File EL-0387HighResolvedData Breach / Extortion with Data Exfiltration

McGraw Hill Data Breach

Also filed as ShinyHunters McGraw Hill Hack · McGraw Hill Education Breach

ShinyHunters claimed and McGraw Hill confirmed a data breach involving approximately 13.5 million user and customer records, primarily through a Salesforce misconfiguration or related access.

  • #education
  • #pii
  • #student-data
  • #salesforce
  • #extortion
Notoriety8/10
Event
1 Apr 2026
Disclosed
14 Apr 2026
Target
McGraw Hill
Actor
ShinyHunters
Scale
13.5M people
Status
Resolved

01Summary

In early April 2026, ShinyHunters added McGraw Hill to their leak site claiming theft of 13.5 million records. The company confirmed the incident on April 14, stating unauthorized access to certain systems had occurred. Exposed data included names, email addresses, and other contact information. The breach was part of ShinyHunters' broader campaign targeting Salesforce instances and education sector organizations.

02Background

McGraw Hill is a major educational publishing and learning technology company. Its platforms contain sensitive student, educator, and customer data.

03Key revelations

  1. 01Ongoing risks in Salesforce ecosystems.
  2. 02Education sector remains a prime target.

04Technical analysis

The breach was linked to Salesforce platform access issues common in ShinyHunters' 2025-2026 campaign (often via vishing or OAuth abuse).

Attack vector
Salesforce compromise / Misconfiguration
Attack method
Data exfiltration and extortion
Initial access
Compromised credentials / Third-party integration
Exfiltration
Bulk data extraction

Vulnerabilities exploited

  • Salesforce access control issues

05Threat actor

ShinyHunters is a prolific cybercriminal extortion group known for targeting large datasets via SaaS platforms.

Aliases

  • SH

Attribution sources

  • ShinyHunters leak site
  • BleepingComputer
  • McGraw Hill statements

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • PII
  • Email addresses
  • Contact information
  • Educational records

08Financial damage

Extortion pressure; potential regulatory fines and class-action lawsuits.

09Timeline

  1. 2026-04-01Initial compromise claimed.
  2. 2026-04-14McGraw Hill publicly confirms breach.

10Reaction and fallout

Public reaction

Concern from schools and educators about student data privacy.

11Legal

Ongoing investigations and potential lawsuits.

Civil lawsuits

  • Anticipated class-action lawsuits

12Aftermath

Security improvements

  • Enhanced Salesforce security controls

13Significance and legacy

Significance

Part of ShinyHunters' large-scale education and SaaS campaign in 2026.

Legacy

Further highlighted third-party SaaS risks in education.

14Disclosure and media

Authentication
ShinyHunters leak site

Publishing organisations

  • BleepingComputer
  • Cybernews

15Field notes

  1. 01Part of a wider ShinyHunters campaign affecting multiple education companies.

16Resolution

McGraw Hill confirmed the breach and worked to contain it; data not publicly leaked after extortion process.

17Sources

Official documents

  • McGraw Hill security notice

References

  1. [1]BleepingComputer reports
  2. [2]McGraw Hill statements
Fact sheetEL-0387

Dates

Event
1 Apr 2026
Started
1 Apr 2026
Discovered
1 Apr 2026
Disclosed
14 Apr 2026
Ongoing
No

Target

Organisation
McGraw Hill LLC
Type
Technology Company
Sector
Education / Publishing
Country
United States

Actor

Name
ShinyHunters
Type
Criminal Gang
Motivation
Financial gain through data extortion.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
13,500,000
Records
13,500,000
Sensitivity
High
Published
No
Sold (dark web)
No

Money

Crypto
Likely (standard for extortion)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.