---
title: "McGraw Hill Salesforce-hosted webpage data exposure"
description: "Evidence-backed account of McGraw Hill Salesforce-hosted webpage data exposure, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/mcgraw-hill-salesforce-webpage-data-exposure-2026"
markdown_url: "https://www.ally.security/incidents/mcgraw-hill-salesforce-webpage-data-exposure-2026.md"
stix_url: "https://www.ally.security/incidents/mcgraw-hill-salesforce-webpage-data-exposure-2026/stix.json"
---

# McGraw Hill Salesforce-hosted webpage data exposure

Unauthorized access to limited data on a webpage hosted by Salesforce for McGraw Hill. A verified HIBP corpus associated with the limited webpage exposure described by McGraw Hill.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** McGraw Hill's stated assessment; not a claim that the Salesforce platform itself was compromised.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to limited data on a webpage hosted by Salesforce for [McGraw Hill](https://www.mheducation.com/). [3](#source-3)

## Impact

A verified HIBP corpus associated with the limited webpage exposure described by McGraw Hill. [3](#source-3)

Documented data types include:

- Contact information — Email addresses across the HIBP corpus, with phone numbers and physical addresses appearing inconsistently in some records. [1](#source-1)
- Names — Names listed for some records in the HIBP corpus. [1](#source-1)

A cited record reports 13,500,136 records (Unique email addresses represented in the HIBP corpus; not a McGraw Hill-confirmed number of people, students, customers, users, accounts, files, or total rows; as of 2026-04-16). [3](#source-3)

HIBP reported that more than 100 GB of data across multiple files was later publicly distributed. [1](#source-1)

McGraw Hill said the activity appeared to be part of a broader issue involving a misconfiguration within Salesforce's environment that affected multiple Salesforce customers. [2](#source-2) [3](#source-3)

McGraw Hill said its review found no Social Security numbers, financial account information, or student data from its educational platforms in the exposed information. [2](#source-2) [3](#source-3)

## Timeline

### April 10, 2026 — Documented event

HIBP BreachDate; McGraw Hill did not publicly identify this as an exact intrusion, detection, or containment date. [1](#source-1)

### April 14, 2026 — Public disclosure

Date BleepingComputer published McGraw Hill's direct statement. [3](#source-3)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

Salesforce said it had no indication that its platform was compromised and that the activity was not related to a known vulnerability in its technology. [2](#source-2)

McGraw Hill said the incident did not involve unauthorized access to its Salesforce accounts, customer databases, courseware, or internal systems. [2](#source-2) [3](#source-3)

McGraw Hill said it identified unauthorized access to a limited set of data from a webpage hosted by Salesforce on its platform. [2](#source-2) [3](#source-3)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

McGraw Hill said it was working with Salesforce to strengthen protections and fully address the issue. McGraw Hill investigated with assistance from external cybersecurity experts. McGraw Hill said it immediately secured the affected webpages after discovering the incident. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2) [3](#source-3)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/mcgraw-hill-salesforce-webpage-data-exposure-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### McGraw Hill breach record

advisory · Have I Been Pwned · Apr 16, 2026

<https://haveibeenpwned.com/api/v3/breach/McGrawHill>

<a id="source-2"></a>

### Educational company McGraw Hill says Salesforce misconfiguration led to data leak

news · The Record from Recorded Future News · Apr 15, 2026

<https://therecord.media/mcgraw-hill-data-leak-tied-to-salesforce-misconfiguration>

<a id="source-3"></a>

### McGraw-Hill confirms data breach following extortion threat

news · BleepingComputer · Apr 14, 2026

<https://www.bleepingcomputer.com/news/security/mcgraw-hill-confirms-data-breach-following-extortion-threat/>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: Salesforce said it had no indication that its platform was compromised and that the activity was not related to a known vulnerability in its technology.
2. **Exposed Data Category · 95% confidence · current**  
   McGraw Hill publicly distributed data corpus: Contact information
3. **Resulted In · 90% confidence · current**  
   McGraw Hill publicly distributed data corpus: HIBP reported that more than 100 GB of data across multiple files was later publicly distributed.
4. **Affected Organization · 100% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: McGraw Hill
5. **Resulted In · 100% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: McGraw Hill said it was working with Salesforce to strengthen protections and fully address the issue.
6. **Resulted In · 95% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: McGraw Hill publicly distributed data corpus
7. **Occurred At · 80% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: 2026-04-10
8. **Resulted In · 100% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: McGraw Hill investigated with assistance from external cybersecurity experts.
9. **Resulted In · 100% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: McGraw Hill said the incident did not involve unauthorized access to its Salesforce accounts, customer databases, courseware, or internal systems.
10. **Resulted In · 100% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: McGraw Hill said it identified unauthorized access to a limited set of data from a webpage hosted by Salesforce on its platform.
11. **Resulted In · 100% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: McGraw Hill said it immediately secured the affected webpages after discovering the incident.
12. **Disclosed At · 100% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: 2026-04-14
13. **Exposed Record Count · 100% confidence · current**  
   McGraw Hill publicly distributed data corpus: 13,500,136 record
14. **Resulted In · 100% confidence · current**  
   April 2026 McGraw Hill Salesforce-hosted webpage incident: McGraw Hill said the activity appeared to be part of a broader issue involving a misconfiguration within Salesforce's environment that affected multiple Salesforce customers.
15. **Exposed Data Category · 95% confidence · current**  
   McGraw Hill publicly distributed data corpus: Names
16. **Resulted In · 100% confidence · current**  
   McGraw Hill publicly distributed data corpus: McGraw Hill said its review found no Social Security numbers, financial account information, or student data from its educational platforms in the exposed information.

</details>
