← All incidents
Resolved, last updated June 2026
K-12 assessment vendorFormer-employee credentialFTCSpecial education dataData minimization

Illuminate Education Breach and FTC Settlement

2021 breach, 2026 FTC order. A former employee’s still-active login exposed the records of more than 10 million students, including special-education status, IEP details, and disciplinary records. The vendor denied it for weeks. The FTC order, finalized June 5, 2026, became the data-minimization benchmark for EdTech.

TL;DR

In late December 2021, an attacker used a former employee's still-active credentials to break into Illuminate Education's cloud databases and download unencrypted files exposing more than 10 million current and former K-12 students. The records included sensitive fields like special-education status, IEP details, disciplinary records, and coded medical conditions. Illuminate denied a compromise for weeks, did not confirm it until roughly March 2022, and failed to notify some districts (covering about 380,000 students) for nearly two years. The fallout ran for years: a $5.1 million settlement with California, Connecticut, and New York in November 2025, and an FTC consent order proposed in December 2025 and given final approval on June 5, 2026.

Timeline

  • December 28, 2021 to January 8, 2022: Breach window. An attacker accesses Illuminate databases with a former employee's credentials and downloads unencrypted files.
  • January 2022: Platform service interruptions. Illuminate initially denies any data compromise.
  • ~March 2022: Illuminate confirms hackers accessed a database holding roughly 820,000 NYC students' data. NYC criticizes the delay.
  • November 6, 2025: California, Connecticut, and New York announce a $5.1 million multistate settlement.
  • December 1, 2025: The FTC announces its proposed consent order and three-count complaint.
  • June 5, 2026: The FTC gives final approval to a modified order, strengthening the data-minimization language after public comment.

Confirmed exposed

  • Names, birth dates, state and student ID numbers
  • Demographics: gender, ethnicity, languages spoken
  • Special education status and IEP details
  • Disciplinary records, accommodation information, coded medical conditions
  • Free/reduced-price lunch participation, English Language Learner status, grades and testing

Confirmed not exposed

  • For the NYC dataset specifically, Social Security numbers and family financial data were not part of the compromised database

The federal FTC scope is described more broadly and includes email and mailing addresses, dates of birth, school records, and health-related information.

Scale

The FTC's final release cites about 10.1 million students across hundreds of districts in multiple states. New York alone: roughly 1.7 million students from about 750 schools, with the NYC dataset covering about 820,000 students. California: about 434,000 students had sensitive information stolen. The two largest districts in the country, NYC and Los Angeles Unified, were both hit. These counts come from different actions and datasets, so each carries its own scope rather than summing into one number.

The FTC consent order (final, June 5, 2026)

The FTC alleged Illuminate violated Section 5 of the FTC Act by failing to use reasonable security, misrepresenting that it protected student data, and misrepresenting that it would provide timely breach notifications. The 10-year order, shorter than the FTC's traditional 20-year term, requires Illuminate to:

  • Maintain a comprehensive information security program with access controls and MFA, annual CISO certification, and third-party assessments.
  • Delete personal information not reasonably needed, and not collect or retain data that is not reasonably necessary (the data-minimization language the FTC strengthened in the final version).
  • Publish and follow a public data-retention schedule.
  • Not misrepresent its data-security and privacy practices, and notify the FTC of any breach it reports to another agency.

There is no monetary penalty in the federal FTC order. The $5.1 million came from the separate state Attorney General settlement.

Why it matters for districts

A vendor's "we take security seriously" is not enough. Illuminate ignored flagged vulnerabilities, left student records in plaintext, kept data it no longer needed, and sat on notifications. Both state AGs and the FTC held it accountable years later. Treat data minimization, retention schedules, and timely-notification clauses as contract terms you verify, not assurances you accept.

Sources

  1. FTC — Action against Illuminate Education for failing to secure student data (proposed order, 2025-12-01)
  2. FTC — Final approval of order against Illuminate (2026-06-05)
  3. Federal Register — Illuminate Education proposed consent order (2025-12-04)
  4. EPIC — FTC Finalizes Settlement with Illuminate Education (2026-06)
  5. Covington Inside Privacy — 10-year information security consent orders (2025-12)
  6. K-12 Dive — Illuminate Education reaches settlement with FTC over 2021 data breach (2025-12)
  7. NY Attorney General — $5.1 million multistate settlement (2025-11-06)
  8. Troutman Pepper — Key takeaways from the CA/CT/NY $5.1M settlement (2025-11)
  9. THE Journal — List of K-12 schools impacted by Illuminate breach (2022-05)
  10. ConsumerAffairs — FTC cracks down on EdTech company after student data breach (2025-12-01)

This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].

Illuminate Education Breach and FTC Settlement: 2021 breach, 2026 FTC order | Ask Before You App