Desk live·
ForensicPost
Breaches/Education/File 26-0414

Misconfigured Salesforce Environment Exposed 13.5 Million McGraw Hill Accounts

A misconfigured Salesforce environment at McGraw Hill exposed around 13.5 million accounts. No intrusion technique is required to describe this one, which is what makes it awkward.

Constructed geometry · not a chart of case data
TargetMcGraw Hill
ActorShinyHunters
D. Kennedy8 min readConfidence: medium1 source reviewed

Around 13.5 million accounts, described at about 100 GB of customer contact details, were taken from a misconfigured Salesforce environment at the education publisher McGraw Hill.

There is no exploit chain to narrate. The environment was configured to permit access, and access was taken. Files of this kind are the least dramatic and among the most common.

Configuration Is Not A Lesser Failure

A misconfiguration tends to be reported apologetically, as though a real attack would have involved more technique. From the position of an affected person the distinction is meaningless: their data was reachable by people who should not have reached it.

It is arguably the more serious failure mode, because there is no adversary sophistication to appeal to. Nobody had to be clever.

Education Publishing Holds Long-Lived Records

Publishers accumulate accounts across school and university cohorts and rarely delete them, because a former student may return, and because deletion has costs while retention appears free.

The consequence is that a substantial share of 13.5 million accounts probably belong to people who last used the product years ago and would be surprised to learn a current record exists. Retention policy is the control that would have reduced this, and it is treated as a compliance chore rather than a security measure.

How we reported this

Compiled from public reporting, listed below. The specific misconfiguration has not been described in detail publicly and we are not speculating. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary