Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

McGraw Hill, Inc. (mheducation.com)

mheducation.com

Discovered 2026-04-12 02:10 UTC
Est. attack date 2026-04-11
Country US

Description:

Over 45M Salesforce records containing PII data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK

Infostealer activity detected by HudsonRock

Compromised Employees: 22

Compromised Users: 70747

Third Party Employee Credentials: 76


External Attack Surface: 111


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabusecscglobal.com
MX Records
  • mxb-00363701.gslb.pphosted.com. Proofpoint
  • mxa-00363701.gslb.pphosted.com. Proofpoint
TXT Records
  • asv=8b051e8264b0157766b0f0ca9e727afd
  • facebook-domain-verification=jmucfz5agnyrro97dnvyagbmvx5o18
  • google-site-verification=8V7kN5CIvny969sc05QlJkMNRCDAFOdmom27W3WB5HE
  • sfEnvUrl = 'https://mh--dev.sandbox.my.salesforce.com'
  • sfContentUrl = 'https://d.la2-c1cs-ia5.salesforceliveagent.com/content'
  • anthropic-domain-verification-s041y7=euKjnfaw8mhUS1vjnGtUnyuhd
  • amazonses:c0nhtnSNNxXqHNK9iy8SSVI1qj1DDadpwmIEiRKAv98=
  • amazonses:MGqHru9vHXwtjv6chSNbA9u+CFog403Li1ZZqLoQWJA=
  • pendo-domain-verification=92a38a43-3bd2-4007-b8be-7294fdda3277
  • figma-domain-verification=f8a35c1b991243122cdc71405b1f75b0c8a35a759e75e9c1318c203d387832cc-1763500311
  • webexdomainverification.4C675B8B79D8B136E053AB06FC0A3F65=98c599cf-9d2f-4319-aa85-a5c4d1993db1
  • virtru-site-verify=TTsZikYt6*mCn-fz87jTeh!3g9**VH.3xTNfEs!J
  • google-site-verification=AJzhGkXacqCr1vHOp3vFEbvkNqjleD3Xw3O0KT2nAoQ
  • atlassian-domain-verification=c7gXeeyIdIRhycDBErnNtWxlaLdJaH8Xe4HRW8opzT9s2oN12uSQAMt/uwuQHErb
  • google-site-verification=WxPEEvrengXOlaM-QNci58faN8YYTU9NlHChMmVjDR0
  • apple-domain-verification=1lJD7yCkNLx70BGU
  • sfEnvUrlPod = 'https://mh--dev.sandbox.my.site.com'
  • sfEmbdServiceUrl = 'https://mh--dev.my.salesforce.com/embeddedservice/5.0/esw.min.js'
  • figma-domain-verification=d7249675b732b693c2d795fab480fc4ca609f8d8a26a7a37105b47654a1313b5-1762875396
  • v6grhjx01dxk5yjjfn1cmg0tpbgpll6f
  • klaviyo-site-verification=Ugs4T4
  • hpe-greenlake-domain-verification=69637752352d5a4b39503633484548785a595a315948577668596b496a717173
  • pendo-domain-verification=402cbc8d-0f07-4299-b6db-6df6f6323e42
  • v=spf1 include:_spf2.mheducation.com a:mx.brainshark.com include:amazonses.com include:mktomail.com include:spf.protection.outlook.com include:_spf.salesforce.com include:spf-00363701.pphosted.com -all
  • figma-domain-verification=ea3477b1f8e715593349bd1ce1979c58a5beadf0a10e904d501a3444028b87ed-1763045434
  • amazonses:29ZQ0rqs3F93+tDQVLe8cI3rSaDKO+Qi8hl/iySiick=
  • jamf-site-verification=UM34-Qn-quR-NA0uumS1DA
  • cisco-ci-domain-verification=4be5ec8f692cac532be02675d994632e86b8ec5ffd60df0ab03e0fc88f8e6619
  • google-site-verification=oFO4uswKeYaeUxGm_B7UQ8U3m2ZtNk0Q21uqfGDp568
  • onetrust-domain-verification=1f5b083b2c4749c391bbf4d9656891bd
  • sfOrgId = '00D6C0000009yRZ'
  • liClWoeZEad9pMYaMIZz2jqKd0U
  • sfChatUrl = 'https://d.la2-c1cs-ia5.salesforceliveagent.com/chat'
  • google-site-verification=1SrHQrsSKlaeICKr7JUyP2ac3FBE7GrDArejeqsNek8
  • docker-verification=c3d7b8b9-cb16-4eb7-8d81-0974e72e0a0c
  • amazonses:sInK/zhtrYvi9X6AyK4c5Ggi/eC9R8CRW7uMsuY/sgA=
  • extensis-domain-verification=c523eb99-270b-4f84-9236-7b9815eb8ffd
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail Docker Salesforce Anthropic Marketo JamF Cisco OneTrust Proofpoint Cisco Webex