McGraw-Hill confirms limited non-sensitive data exposure via misconfigured Salesforce page; ShinyHunters claims 45M PII records and threatens leak; investigation ongoing.
| IOC Type | Value | Description | Relevant MITRE ATT&CK Techniques |
|---|---|---|---|
| Threatactor | ShinyHunters | APT group using Google Cloud credential scraping, MFA bypass via voice phishing, and trufflehog for lateral movement | None |
| Code | Title |
|---|---|
| T1190 | Exploit Public-Facing Application to access misconfigured Salesforce page |
| T1078.004 | Use of valid cloud credentials (cloud accounts) to access data |
| T1567.001 | Exfiltration Over Web Services |
| Type | Value |
|---|---|
| Sector | Education publishing |
Education company McGraw-Hill has confirmed in a statement to BleepingComputer that hackers exploited a Salesforce misconfiguration and accessed its internal data. The company assured that the breach did not affect its Salesforce accounts, customer databases, or internal systems, and that the amount of exposed data is limited and non-sensitive. “McGraw-Hill recently identified unauthorized access to a limited set of data from a webpage hosted by Salesforce on its platform. This activity appears to be part of a broader issue involving a misconfiguration within Salesforce’s environment that has impacted multiple organizations that work with Salesforce," a McGraw-Hill spokesperson told BleepingComputer. "Importantly, this did not involve unauthorized access to McGraw-Hill’s Salesforce accounts, customer databases, courseware, or internal systems,” the company representative added. McGraw-Hill further states that its investigation, with help from external cybersecurity experts, revealed that the exposed information does not contain Social Security numbers (SSNs), financial account information, or student data from its educational platforms. A global education company focused on learning content and platforms, McGraw-Hill offers textbooks, digital learning platforms, and K-12 school and university systems. The company is a major player in
McGraw-Hill on