← All incidents
Resolved, last updated 2021
EdTech vendorSECDownplaying a breachUnpatched vulnerability

Pearson AIMSweb Breach and SEC Action

2018 breach, 2021 SEC fine. The definitive "downplaying the breach" case. Pearson described an actual breach as a hypothetical risk, and the SEC fined it $1 million. The lesson is about honest disclosure.

What happened

EdTech publishing giant Pearson suffered a 2018 intrusion into its AIMSweb 1.0 student-assessment platform. Pearson had failed to patch a known critical vulnerability for roughly six months. The SEC later fined Pearson $1 million for misleading investors by describing the breach as a hypothetical risk rather than an event that had already happened.

Confirmed exposed

  • Student dates of birth and email addresses
  • Administrator login credentials
  • Millions of records tied to 13,000 school district and university customer accounts

Confirmed not exposed

  • The SEC action centered on disclosure conduct, not only the technical breach

Why it belongs in this library

How a vendor talks about a breach matters as much as the breach. Describing a real incident as a hypothetical is the failure mode districts should watch for, and the reason a district's own honest, timely notification is worth more than a vendor's reassurance.

Sources

  1. SEC — Charges Pearson plc for Misleading Investors About Cyber Breach (2021-08)
  2. BleepingComputer — Education giant Pearson fined $1M for downplaying data breach (2021)

This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].

Pearson AIMSweb Breach and SEC Action: 2018 breach, 2021 SEC fine | Ask Before You App