Loading...

ShinyHunters Expands Extortion Campaign With New Houghton Mifflin Harcourt Claim

ShinyHunters has added education publisher Houghton Mifflin Harcourt to its extortion campaign, warning of a May 2026 data leak deadline after claiming prolonged unauthorized access to the company's systems.
Screenshot showing a new ShinyHunters leak-site listing targeting Houghton Mifflin Harcourt alongside a rare public statement issued by the threat group regarding its ongoing campaign.
Screenshot of the ShinyHunters leak site displaying an alleged extortion post targeting Houghton Mifflin Harcourt and a separate public statement from the threat group.

ShinyHunters has issued a rare public statement amid its ongoing extortion campaign, while adding education publisher Houghton Mifflin Harcourt Company to its leak site with a new pay-or-leak warning.

Houghton Mifflin Harcourt, commonly known as HMH, is a major U.S.-based educational publishing and learning technology company providing textbooks, digital classroom platforms, curriculum software, and assessment services used by schools and educators worldwide.

The threat group claimed Houghton Mifflin Harcourt data was compromised across “several campaigns throughout the past few months,” suggesting what may have been a prolonged intrusion or repeated access attempts tied to the organization.

The listing included a May 12, 2026 deadline demanding the company engage with the group before allegedly stolen data is leaked publicly. The post also threatened unspecified “digital problems” if negotiations fail.

At time of publication, BreachNews could not independently verify whether any Houghton Mifflin Harcourt systems were compromised or whether any data was exfiltrated.

ShinyHunters signals mounting pressure

Alongside the new victim listing, ShinyHunters published a short public statement claiming the group was receiving a significant volume of media inquiries regarding what it described as a “global incident.”

The statement said the group would not provide additional public comment regarding the ongoing activity.

The messaging reflects an increasingly public-facing posture from the threat group as more organizations linked to recent extortion claims acknowledge unauthorized access incidents, customer-data exposure, or internal security investigations.

Over recent weeks, ShinyHunters has repeatedly targeted enterprise cloud environments, CRM systems, customer databases, and internal support infrastructure across multiple sectors including telecommunications, education, financial services, and SaaS platforms.

Several organizations previously listed by the group later confirmed security incidents, including Vercel, Vimeo, and Instructure.

The group’s latest posts continue to blur the line between traditional data-extortion operations and broader coordinated intrusion campaigns targeting enterprise infrastructure and cloud-connected business systems.

Houghton Mifflin Harcourt had not issued any public statement regarding the allegations at time of publication.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Related Posts

Newsletter signup

Get the latest data breach and security news.

Please wait...

Thank you for signing up!

BREACHNEWS.COM

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site