Around 13.5 million accounts, described at about 100 GB of customer contact details, were taken from a misconfigured Salesforce environment at the education publisher McGraw Hill.
There is no exploit chain to narrate. The environment was configured to permit access, and access was taken. Files of this kind are the least dramatic and among the most common.
Configuration Is Not A Lesser Failure
A misconfiguration tends to be reported apologetically, as though a real attack would have involved more technique. From the position of an affected person the distinction is meaningless: their data was reachable by people who should not have reached it.
It is arguably the more serious failure mode, because there is no adversary sophistication to appeal to. Nobody had to be clever.
Education Publishing Holds Long-Lived Records
Publishers accumulate accounts across school and university cohorts and rarely delete them, because a former student may return, and because deletion has costs while retention appears free.
The consequence is that a substantial share of 13.5 million accounts probably belong to people who last used the product years ago and would be surprised to learn a current record exists. Retention policy is the control that would have reduced this, and it is treated as a compliance chore rather than a security measure.
Compiled from public reporting, listed below. The specific misconfiguration has not been described in detail publicly and we are not speculating. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense