Chegg FTC Enforcement
Order finalized January 2023. The benchmark FTC EdTech security-enforcement action. Four breaches, plaintext data, no MFA, and a regulator holding a vendor accountable for its practices, not just a single event.
What happened
The FTC charged study-help provider Chegg over four separate data breaches caused by lax security and finalized an order in January 2023 requiring a comprehensive security overhaul. The personal data of about 40 million users and employees was exposed across the four incidents.
Confirmed exposed
- Email addresses and account data
- Sensitive scholarship-application data: dates of birth, sexual orientation, disabilities
- Financial and medical information on employees
Confirmed not exposed
- The FTC action focused on Chegg practices, including passwords stored with weak encryption and other data stored in plain text
Why it belongs in this library
Regulators will hold a vendor accountable for how it stores and protects data (plaintext storage, no MFA), not only for the fact of a breach. The order is the template for what "reasonable security" is supposed to mean.
Sources
This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].