Salesforce Misconfiguration Exposes Tenant Data Without Account Breach
A Salesforce-hosted webpage can leak tenant data even when the customer’s Salesforce accounts, databases, and internal systems stay untouched. That breaks the usual assumption that account security alone contains platform risk; the exposure can sit in the vendor layer and still reach customer data.
McGraw-Hill says unauthorized access reached a limited set of non-sensitive data from a webpage hosted by Salesforce, and that no student data, SSNs, financial account data, or internal systems were involved. The company says the issue reflects a broader Salesforce misconfiguration that has affected multiple organizations, and the disclosure followed extortion claims from ShinyHunters.
The forward risk is stealthy and shared across tenants. If the misconfiguration sits in the platform layer, other Salesforce customers can face data exposure without any sign of account compromise, which makes this a broader SaaS trust problem rather than a single-company breach.