Educational company McGraw Hill says Salesforce misconfiguration led to data leak
嗯,用户让我用中文帮他总结一篇文章,控制在100字以内,而且不需要特定的开头。首先,我需要仔细阅读这篇文章,理解主要内容。 文章讲的是McGraw Hill公司的一个数据泄露事件。他们提到是因为Salesforce数据库配置错误导致的非敏感信息泄露。发言人说明没有涉及客户账户、数据库等重要信息。ShinyHunters黑客组织声称窃取了4500万条记录,并威胁要泄露。McGraw Hill已经采取措施应对,并与Salesforce合作加强保护。 接下来,我需要把这些关键点浓缩到100字以内。确保包括事件原因、影响范围、处理措施和结果。同时,语言要简洁明了,不使用复杂的句子结构。 可能的结构是:公司名称 + 事件原因 + 影响 + 处理措施 + 结果。比如:“教育公司McGraw Hill因Salesforce数据库配置错误导致非敏感信息泄露,未涉及客户账户和内部系统。黑客组织ShinyHunters声称窃取4500万条记录并威胁泄露,公司已采取措施应对。” 这样既涵盖了主要信息,又符合字数限制。 </think> 教育公司McGraw Hill因Salesforce数据库配置错误导致非敏感信息泄露,未涉及客户账户和内部系统。黑客组织ShinyHunters声称窃取4500万条记录并威胁泄露,公司已采取措施应对。 2026-4-15 14:35:39 Author: therecord.media(查看原文) 阅读量:4 收藏

Educational company McGraw Hill said a limited breach of non-sensitive information was tied to a misconfiguration involving a Salesforce database that has impacted multiple organizations.

A spokesperson for McGraw Hill said the company recently “identified unauthorized access to a limited set of data from a webpage hosted by Salesforce on its platform.”

“This activity appears to be part of a broader issue involving a misconfiguration within Salesforce’s environment that has impacted multiple organizations that work with Salesforce,” the spokesperson said. “Importantly, this did not involve unauthorized access to McGraw Hill’s Salesforce accounts, customer databases, courseware, or internal systems.”

The data breach emerged this weekend when the ShinyHunters cybercriminal organization claimed to have stolen 45 million Salesforce records and threatened to leak the information by April 14 if a ransom was not paid. 

The company was added to the cybercriminals’ leak site along with several other notable companies, including Rockstar Games.

The McGraw Hill spokesperson said that when the incident was discovered, they immediately secured the affected webpages and started an investigation. A review of the stolen data found that it is “limited in scope and consists of non-sensitive information.” 

McGraw Hill is one of the largest educational companies in the world, providing educational content, software and services to grade schools, universities and companies. It reported $434.2 million in revenue last quarter. 

McGraw Hill did not say how many people were affected by the incident, but said it did not involve information like Social Security numbers, financial information or student data. 

The company noted that it is working with Salesforce to “further strengthen protections and ensure this issue is fully addressed.” 

A Salesforce spokesperson said there is “no indication that the Salesforce platform has been compromised,” and said the recent cybercriminal activity “is not related to any known vulnerability in our technology.”

Salesforce customers have been repeatedly targeted by hackers connected to ShinyHunters since last year during several of the gang’s campaigns targeting various industries. After a string of high-profile, damaging cyberattacks on the insurance, retail and aviation industries, members of the group were arrested and charged by law enforcement agencies in the U.S. and U.K.

A lull in activity followed the arrests but the group resurfaced earlier this year with attacks on dating app companies Bumble and Match Group, Canada Goose, the University of Pennsylvania and the European Commission.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.


文章来源: https://therecord.media/mcgraw-hill-data-leak-tied-to-salesforce-misconfiguration
如有侵权请联系:admin#unsafe.sh