McGraw Hill confirmed a data breach in April 2026 affecting 13.5 million accounts, exposing email addresses, names, phone numbers, and physical addresses due to a Salesforce misconfiguration.
What happened
According to HIBP, McGraw Hill confirmed a data breach in April 2026 following an extortion attempt. The incident was attributed to a Salesforce misconfiguration that exposed data from a webpage hosted on Salesforce's platform. More than 100GB of data was subsequently distributed publicly.
What was exposed
The breach exposed 13.5 million unique email addresses. Additional fields including names, physical addresses, and phone numbers appeared inconsistently across some records in the distributed files.
Who is affected
Approximately 13.5 million individuals with accounts or data associated with McGraw Hill's Salesforce-hosted webpage are affected by this breach.
What to do now
Affected individuals should monitor their email accounts and watch for unsolicited contact. Consider placing a fraud alert or credit freeze with credit bureaus if personal information including addresses and phone numbers were exposed. Review any McGraw Hill accounts for unauthorized activity.