McGraw Hill confirmed that attackers accessed a limited set of internal data through a misconfigured Salesforce-hosted webpage, after the ShinyHunters extortion group claimed responsibility and threatened to publish stolen information unless a ransom was paid. The company said the incident was tied to a broader issue affecting multiple organizations using Salesforce-hosted environments and maintained that its Salesforce accounts, customer databases, courseware, internal systems, Social Security numbers, financial account information, and student data from its educational platforms were not impacted.
After the extortion deadline passed, data tied to 13.5 million McGraw Hill user accounts was reportedly leaked publicly, with Have I Been Pwned saying the dump contained more than 100GB of files, including unique email addresses and some names, physical addresses, and phone numbers. The leak contradicted earlier company statements that the exposed data was limited and non-sensitive, while ShinyHunters separately claimed to hold 45 million Salesforce records; McGraw Hill said it secured the affected webpages, brought in external cybersecurity experts, and is working with Salesforce to strengthen protections.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A RedPacket Security post reported that ShinyHunters had identified Instructure Holdings, Inc., associated with Canva LMS and instructure.com, as a ransomware/extortion victim. This represents a separate victim disclosure from the previously documented McGraw-Hill incident.
After the extortion threat, ShinyHunters publicly leaked more than 100GB of data tied to 13.5 million McGraw-Hill user accounts. Have I Been Pwned reported the exposed files contained 13.5 million unique email addresses along with some names, physical addresses, and phone numbers.
McGraw-Hill confirmed that attackers accessed a limited set of internal data through a misconfigured webpage hosted on Salesforce. The company said its Salesforce accounts, customer databases, courseware, internal systems, financial data, Social Security numbers, and student platform data were not affected, and that it secured the webpage and engaged external cybersecurity experts.
The ShinyHunters extortion group listed McGraw-Hill on its leak site, claiming it had stolen 45 million Salesforce records containing personally identifiable information. The group threatened to publish the data unless a ransom was paid, with publication set for April 14.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cybernewscentre.com
Open sourcetechrepublic.com
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcerescana.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.