Data breach at edtech giant McGraw Hill affects 13.5 million accounts
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要用“文章内容总结”之类的开头。首先,我需要仔细阅读文章内容,找出关键信息。 文章主要讲的是ShinyHunters勒索团伙入侵了麦格劳-希尔的Salesforce环境,泄露了1350万用户的数据。麦格劳-希尔是全球领先的教育出版商,年收入22亿美元。他们确认了这次入侵,并提到是由于Salesforce环境的配置错误导致的。泄露的信息包括姓名、地址、电话和邮箱,可能被用于钓鱼攻击。 接下来,我需要把这些信息浓缩到100字以内。重点包括:勒索团伙、入侵时间、受影响人数、数据类型以及可能的影响。 可能会遗漏一些细节,比如其他公司也被入侵了,但为了简洁起见,可能不需要提到。确保语言简洁明了,直接描述事件。 最后检查一下字数,确保不超过限制,并且没有使用禁止的开头方式。 </think> ShinyHunters勒索团伙入侵麦格劳-希尔公司Salesforce环境,泄露1350万用户数据。事件因配置错误引发,涉及姓名、地址、电话和邮箱等信息,或被用于钓鱼攻击。 2026-4-16 10:46:32 Author: www.bleepingcomputer.com(查看原文) 阅读量:16 收藏

McGraw Hill

The ShinyHunters extortion group has leaked data from 13.5 million McGraw Hill user accounts, stolen after breaching the company's Salesforce environment earlier this month.

Founded in 1909, McGraw Hill is a leading global educational publisher with annual revenue of $2.2 billion, which provides education content and solutions for PreK–12, higher education, and professional learning.

The company confirmed ShinyHunters' breach claims in a statement shared with BleepingComputer on Tuesday, saying the threat actors exploited a misconfiguration in the compromised Salesforce environment and that the incident didn't affect its Salesforce accounts, courseware, customer databases, or internal systems.

Wiz

"McGraw-Hill recently identified unauthorized access to a limited set of data from a webpage hosted by Salesforce on its platform. This activity appears to be part of a broader issue involving a misconfiguration within Salesforce's environment that has impacted multiple organizations that work with Salesforce," a McGraw-Hill spokesperson told BleepingComputer.

This came after ShinyHunters added the company to the gang's dark web leak site, claiming to have stolen 45 million Salesforce records containing personally identifiable information (PII) and threatening to leak the allegedly stolen documents online unless a ransom is paid.

McGraw Hill entry on ShinyHunters' extortion portal
McGraw Hill entry on ShinyHunters' data leak site (BleepingComputer)

​While McGraw Hill has yet to share how many individuals were affected by the resulting data breach, data breach notification service Have I Been Pwned says ShinyHunters has now leaked over 100GB of files containing data linked to 13.5 million accounts.

The exposed information includes names, physical addresses, phone numbers, and email addresses, which threat actors could use to target McGraw Hill customers in spear-phishing attacks.

"In April 2026, education company McGraw Hill confirmed a data breach following an extortion attempt. Attributed to a Salesforce misconfiguration, the company stated the incident exposed 'a limited set of data from a webpage hosted by Salesforce on its platform'," Have I Been Pwned said today.

"More than 100GB of data was later publicly distributed, containing 13.5M unique email addresses across multiple files, with additional fields such as name, physical address and phone number appearing inconsistently across some records."

This week, ShinyHunters has also started leaking data stolen after breaching the Snowflake environment of American video game publisher Rockstar Games. The stolen data includes internal analytics used to monitor Rockstar's online services and support tickets, as well as in-game revenue and purchase metrics, player behavior tracking, and game economy data for Red Dead Online and Grand Theft Auto Online.

In recent months, the extortion gang was also behind security breaches affecting the European Commission, Infinite Campus, Hims & Hers, Telus Digital, Wynn Resorts, CarGurus, Panera Bread, SoundCloud, and dating giant Match Group.

tines

Automated Pentesting Covers Only 1 of 6 Surfaces.

Automated pentesting proves the path exists. BAS proves whether your controls stop it. Most teams run one without the other.

This whitepaper maps six validation surfaces, shows where coverage ends, and provides practitioners with three diagnostic questions for any tool evaluation.


文章来源: https://www.bleepingcomputer.com/news/security/data-breach-at-edtech-giant-mcgraw-hill-affects-135-million-accounts/
如有侵权请联系:admin#unsafe.sh