← All incidents
Resolved, last updated 2023
EdTech vendorFTCFour breachesPlaintext storageNo MFA

Chegg FTC Enforcement

Order finalized January 2023. The benchmark FTC EdTech security-enforcement action. Four breaches, plaintext data, no MFA, and a regulator holding a vendor accountable for its practices, not just a single event.

What happened

The FTC charged study-help provider Chegg over four separate data breaches caused by lax security and finalized an order in January 2023 requiring a comprehensive security overhaul. The personal data of about 40 million users and employees was exposed across the four incidents.

Confirmed exposed

  • Email addresses and account data
  • Sensitive scholarship-application data: dates of birth, sexual orientation, disabilities
  • Financial and medical information on employees

Confirmed not exposed

  • The FTC action focused on Chegg practices, including passwords stored with weak encryption and other data stored in plain text

Why it belongs in this library

Regulators will hold a vendor accountable for how it stores and protects data (plaintext storage, no MFA), not only for the fact of a breach. The order is the template for what "reasonable security" is supposed to mean.

Sources

  1. FTC — Finalizes Order with Ed Tech Provider Chegg for Lax Security that Exposed Student Data (2023-01)

This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].

Chegg FTC Enforcement: Order finalized January 2023 | Ask Before You App