[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f304pbfuu82nfk":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":13,"affectedCountUnit":24,"hasEnglishDescription":4,"contentLocale":25,"availableLocales":26,"translations":28,"severity":31,"dataClasses":32,"description":37,"seoTitle":38,"seoDescription":39,"logoUrl":40,"isVerified":4,"isSensitive":41,"isSpamList":41,"isMalware":41,"company":42},"6a452308a20f867c8ba8e758","McGrawHill","McGraw Hill Data Breach","mcgraw-hill","mheducation.com","2026-04-10T00:00:00.000Z","2026-04-16T01:31:14.000Z",null,"2026-04-16T01:38:51.000Z","2026-07-20T06:43:30.777Z","Config exposure","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmcgraw-hill-confirms-data-breach-following-extortion-threat\u002F",[17,19,20,21],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fdata-breach-at-edtech-giant-mcgraw-hill-affects-135-million-accounts\u002F","https:\u002F\u002Fwww.cyberdaily.au\u002Fsecurity\u002F13479-mcgraw-hill-confirms-shinyhunters-breach-won-t-confirm-if-any-aussie-customers-impacted","https:\u002F\u002Fwww.mheducation.com\u002F",13500136,"known","unknown","en",[25,27],"tr",{"en":29,"tr":30},{"slug":9},{"slug":9},"Critical",[33,34,35,36],"Email addresses","Names","Phone numbers","Physical addresses","\u003Cp>The \u003Cstrong>McGraw Hill data breach\u003C\u002Fstrong> is a verified incident dated 10 April 2026 involving 13,500,136 unique email addresses.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The publicly distributed files contained \u003Cstrong>13,500,136 unique email addresses\u003C\u002Fstrong>, while names, phone numbers and physical addresses appeared only in some records and files. The unique-email total therefore does not mean that every exposed field affected the same number of people. The company said Social Security numbers, financial account information and student data from its educational platforms were not involved. There is also no verified evidence that passwords or payment card details were present, so those fields are not listed as exposed data classes. The attacker’s claim of 45 million records is not a verified unique-account count. A person may appear across several rows or files, so total records and unique email addresses must be treated as different measures.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The incident was linked to a configuration issue on a McGraw Hill webpage hosted on the Salesforce platform, which allowed unauthorised access to a limited dataset. The company said the activity did not involve unauthorised access to its Salesforce accounts, customer databases, courseware or internal systems. The affected pages were secured after discovery and an investigation began with cybersecurity specialists. A cybercrime group claimed on 12 April that it held 45 million personal-data records and demanded payment by 14 April. More than 100 GB was subsequently distributed publicly; deduplication across multiple files identified 13,500,136 unique email addresses. The date 10 April 2026 is the catalogue date for the incident, while confirmation and public distribution occurred in mid-April. The supported technical cause is a configuration exposure affecting the Salesforce-hosted webpage.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The people most directly at risk are those whose email addresses appear in the distributed files. Because names, phone numbers or physical addresses occur in only some records, the level of exposure varies by person. It should not be assumed that everyone in the files was a student, teacher, employee or active customer; available evidence does not provide a separate affected-person count for each group. According to the company, student data in its educational platforms was outside the incident scope. A match does not show that an account password was stolen because no password exposure was confirmed. Attackers can still use a known email address and name to prepare fraudulent password resets, document-sharing notices or payment messages.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Independently verify the sender domain and purpose of any unexpected email, text message or call claiming to come from McGraw Hill or Salesforce before following a link. Be particularly cautious when a message uses an invoice, educational material, account closure, copyright notice or breach compensation as a reason to request a password, one-time code or payment. \u003Cstrong>Enable two-step verification on the email account\u003C\u002Fstrong>, then review its recovery options and active sessions. Because password exposure was not confirmed, avoid reset links sent in unsolicited messages; if the same password is reused elsewhere, replace it with a unique password on every account. If a phone number appeared in the record, monitor carrier notifications for SIM replacement, fake support and voice-phishing attempts. People whose physical address was exposed should independently verify unfamiliar delivery and billing requests.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Email addresses and contact details often remain unchanged for years, so the risk does not end a few weeks after publication. Use a password manager to maintain a different long password for every account and prefer app-based or security-key authentication for important services. Periodically review email forwarding rules, connected applications and recovery addresses. A message that correctly states a name, address or phone number is not automatically trustworthy; contact the institution through a known website or phone number. If a work or school address was affected, send suspicious messages to the organisation’s security team and warn colleagues about the same campaign. Even obsolete contact information can support a believable story about a past customer relationship or educational service. When another copy or a different total appears, determine whether it counts unique people, unique emails, rows or individual data points before comparing it with the established figure.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Search LeakData.io with an email address that may have been used with McGraw Hill to see whether it matches this record. A match means the address appeared in at least one distributed file; it does not mean that a name, phone number and physical address were all present in the same record. An empty result does not prove that entries created with another address are absent, so check old work, school and personal addresses separately. Never provide a password, one-time code, student number, payment information or identity document in response to a search result. If a match appears, secure the email account first and then review important services that use the address as a username or recovery channel. When assessing new McGraw Hill breach figures, do not compare the attacker’s 45 million-record claim with 13,500,136 unique email addresses as though they were the same measure. Periodic checks and early reporting of suspicious contact can reduce phishing risk after the incident.\u003C\u002Fp>","McGraw Hill Data Breach (13.5 Million Reported Records)","McGraw Hill Data Breach. 13.5 Million reported records are reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fmheducation_com.webp",false,{"name":43,"sector":44,"country":45,"website":10,"websiteArchiveUrl":46,"websiteStatus":46,"websiteCheckedAt":13},"McGraw Hill","Education","United States",""]