Summary
- Environment: McGraw Hill's stated assessment; not a claim that the Salesforce platform itself was compromised.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Unauthorized access to limited data on a webpage hosted by Salesforce for McGraw Hill. [3]
Impact
A verified HIBP corpus associated with the limited webpage exposure described by McGraw Hill. [3]
Documented data types include:
- Contact information — Email addresses across the HIBP corpus, with phone numbers and physical addresses appearing inconsistently in some records. [1]
- Names — Names listed for some records in the HIBP corpus. [1]
A cited record reports 13,500,136 records (Unique email addresses represented in the HIBP corpus; not a McGraw Hill-confirmed number of people, students, customers, users, accounts, files, or total rows; as of 2026-04-16). [3]
HIBP reported that more than 100 GB of data across multiple files was later publicly distributed. [1]
McGraw Hill said the activity appeared to be part of a broader issue involving a misconfiguration within Salesforce’s environment that affected multiple Salesforce customers. [2][3]
McGraw Hill said its review found no Social Security numbers, financial account information, or student data from its educational platforms in the exposed information. [2][3]
Timeline
Threat Group & Attack Vector
Salesforce said it had no indication that its platform was compromised and that the activity was not related to a known vulnerability in its technology. [2]
McGraw Hill said the incident did not involve unauthorized access to its Salesforce accounts, customer databases, courseware, or internal systems. [2][3]
McGraw Hill said it identified unauthorized access to a limited set of data from a webpage hosted by Salesforce on its platform. [2][3]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
McGraw Hill said it was working with Salesforce to strengthen protections and fully address the issue. McGraw Hill investigated with assistance from external cybersecurity experts. McGraw Hill said it immediately secured the affected webpages after discovering the incident. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2][3]
