McGraw Hill Salesforce-hosted webpage data exposure

Unauthorized access to limited data on a webpage hosted by Salesforce for McGraw Hill. A verified HIBP corpus associated with the limited webpage exposure described by McGraw Hill.

Last modified

Summary

  • Environment: McGraw Hill's stated assessment; not a claim that the Salesforce platform itself was compromised.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to limited data on a webpage hosted by Salesforce for McGraw Hill. [3]

Impact

A verified HIBP corpus associated with the limited webpage exposure described by McGraw Hill. [3]

Documented data types include:

  • Contact information — Email addresses across the HIBP corpus, with phone numbers and physical addresses appearing inconsistently in some records. [1]
  • Names — Names listed for some records in the HIBP corpus. [1]

A cited record reports 13,500,136 records (Unique email addresses represented in the HIBP corpus; not a McGraw Hill-confirmed number of people, students, customers, users, accounts, files, or total rows; as of 2026-04-16). [3]

HIBP reported that more than 100 GB of data across multiple files was later publicly distributed. [1]

McGraw Hill said the activity appeared to be part of a broader issue involving a misconfiguration within Salesforce’s environment that affected multiple Salesforce customers. [2][3]

McGraw Hill said its review found no Social Security numbers, financial account information, or student data from its educational platforms in the exposed information. [2][3]

Timeline

  1. Documented event

    HIBP BreachDate; McGraw Hill did not publicly identify this as an exact intrusion, detection, or containment date.

    [1]
  2. Public disclosure

    Date BleepingComputer published McGraw Hill’s direct statement.

    [3]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Salesforce said it had no indication that its platform was compromised and that the activity was not related to a known vulnerability in its technology. [2]

McGraw Hill said the incident did not involve unauthorized access to its Salesforce accounts, customer databases, courseware, or internal systems. [2][3]

McGraw Hill said it identified unauthorized access to a limited set of data from a webpage hosted by Salesforce on its platform. [2][3]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

McGraw Hill said it was working with Salesforce to strengthen protections and fully address the issue. McGraw Hill investigated with assistance from external cybersecurity experts. McGraw Hill said it immediately secured the affected webpages after discovering the incident. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2][3]