← The Breach Files

2026 · Data breach

McGraw Hill

Breached 10 April 2026 · Published 16 April 2026 · mheducation.com

13,500,136Accounts exposed
67/100Severe severity
4Types of data
VerifiedBy HIBP

On 10 April 2026, McGraw Hill was breached. 13,500,136 accounts were exposed, including email addresses, names, phone numbers. MyRecon rates it 67/100 — severe. That is about 50% of the population of Australia.

Checked against this breach and every other on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Read the disclosure language and the outcome side by side. The company described "a limited set of data from a webpage hosted by Salesforce on its platform". More than 100GB was subsequently published, carrying 13.5 million distinct email addresses. Both statements can be technically accurate at the same time — one describes the surface that was exposed, the other describes what came through it — and that is exactly why a description of the entry point is not a measure of the damage.

The other thing worth noticing is whose data this is. Students and instructors did not choose McGraw Hill; an institution chose it for them, and the record that ended up in a 100GB archive was created as a condition of taking a course. That pattern runs through most education technology breaches, and it is why "stop using the service" is advice that does not apply here.

What happened

In April 2026, education company McGraw Hill confirmed a data breach following an extortion attempt. Attributed to a Salesforce misconfiguration, the company stated the incident exposed "a limited set of data from a webpage hosted by Salesforce on its platform". More than 100GB of data was later publicly distributed, containing 13.5M unique email addresses across multiple files, with additional fields such as name, physical address and phone number appearing inconsistently across some records.

Breach description from Have I Been Pwned, used under a CC BY 4.0 licence.

Who was behind it

No party has been publicly confirmed as responsible, and this page will not name one. Most breaches are never formally attributed: data surfaces on a forum or inside a combined dump long after the intrusion, and the trail back to a specific actor is rarely made public. Where a group has claimed responsibility it is usually named in the account above — that claim is theirs, not a finding of ours.

What was exposed, and why it matters

What to do if you were in it

  1. Move two-factor authentication off SMS and onto an authenticator app, which a SIM swap cannot intercept.
  2. Be sceptical of post and callers who already know your address — knowing it is no longer evidence of anything.
  3. Expect better-aimed phishing. A message that already knows your name and where you have an account is the whole point of a breach like this.

Questions people ask about this breach

Was my email address in the McGraw Hill breach?

Enter it in the box at the top of this page. MyRecon checks it against this breach and every other one on record, and the address is never stored.

What data was leaked in the McGraw Hill breach?

email addresses, names, phone numbers, physical addresses. Each one is explained above, along with what it means for the person it belongs to.

When did it happen, and when did it become public?

The breach is dated 10 April 2026. It was published to Have I Been Pwned on 16 April 2026, a gap of 6 days during which the data was already out.

Is the McGraw Hill breach real?

Yes. Have I Been Pwned lists it as verified, meaning the data was checked against the source rather than taken on trust.

How many people were affected?

13,500,136 accounts. That is about 50% of the population of Australia. That is accounts rather than people — one person often has several.

Read next

Also in the archive

Case Files: how the landmark breaches actually happened →

Three kinds of content appear on this page and they are kept apart deliberately. The breach description is quoted from Have I Been Pwned under its licence. The severity score, the field-by-field explanation and the advice are computed from the record itself — every sentence derives from a number or a flag in it, which is what stops the analysis drifting from the evidence. Anything under the "MyRecon's take" byline is editorial: our reading of this breach, presented as opinion rather than as a finding.

← All breaches