HMH 2025 Data Breach

Houghton Mifflin Harcourt (HMH) Educational Publisher Breach (Salesforce, 2025): 5.3 Million Contact Records Exposed

Platform · Education and academic services · Educational publisher and K-12 learning technology provider · Global

Houghton Mifflin Harcourt (HMH) Educational Publisher Breach (Salesforce, 2025): 5.3 Million Contact Records Exposed

Houghton Mifflin Harcourt - K-12 educational publisher and learning technology provider.

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach involves data relating to children. We do not confirm the presence of any individual publicly or to third parties. A parent or guardian can check exposure privately below.
Breach Risk Index i
77/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
5.3MRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
Classification Tags
Scattered Lapsus$ HuntersSocial EngineeringEducationDirect Customers2025

Breach Summary

In October 2025, HMH (Houghton Mifflin Harcourt) data was published as part of the ShinyHunters / Scattered Lapsus$ Hunters campaign against Salesforce customers, with a sample released on 3 October 2025. The indexed set covers about 5.3 million records centered on names and email addresses.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

5.3M records analyzed

About HMH

Houghton Mifflin Harcourt (HMH) is a major US educational publishing and learning-technology company.

Why They Hold Your Data

Educational publishers and learning-technology providers collect student, teacher, parent, school, billing, and classroom-linked data across curriculum, assessment, and digital-learning workflows.

Data Points Exposed

3 verified field types
Email Address
Phone Number
Physical address High

Breach Impact

The large email/name set supports phishing; given HMHs education focus, some records may relate to educators or students, warranting care.

Exploitation & Downstream Threats

• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

An education-sector breach: student, staff and identity records support identity theft and targeted phishing. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
SL
Threat Actor: Scattered Lapsus$ HuntersConfidence: Medium-High
Coalition / brand fusion

Motivation: Financial, notoriety, extortion
A 2025 claimed fusion of Scattered Spider, LAPSUS$, and ShinyHunters branding. It used Telegram and forum channels for threats, leak theatrics, and extortion pressure.

Read the full threat-actor profile →
This breach is linked to the ShinyHunters / Scattered Lapsus$ Hunters - Salesforce (2025-26) campaign. See the full campaign analysis →

Protect Yourself

Protect Yourself: Limited Disclosure

Check Exposure: Verification Required

Because this breach involves data about minors, we do not confirm whether any individual appears in it to unverified parties. A verified parent, guardian, or the individual can privately check exposure.

We confirm exposure only to the affected individual or their verified parent or guardian.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation