Pearson AIMSweb Breach and SEC Action
2018 breach, 2021 SEC fine. The definitive "downplaying the breach" case. Pearson described an actual breach as a hypothetical risk, and the SEC fined it $1 million. The lesson is about honest disclosure.
What happened
EdTech publishing giant Pearson suffered a 2018 intrusion into its AIMSweb 1.0 student-assessment platform. Pearson had failed to patch a known critical vulnerability for roughly six months. The SEC later fined Pearson $1 million for misleading investors by describing the breach as a hypothetical risk rather than an event that had already happened.
Confirmed exposed
- Student dates of birth and email addresses
- Administrator login credentials
- Millions of records tied to 13,000 school district and university customer accounts
Confirmed not exposed
- The SEC action centered on disclosure conduct, not only the technical breach
Why it belongs in this library
How a vendor talks about a breach matters as much as the breach. Describing a real incident as a hypothetical is the failure mode districts should watch for, and the reason a district's own honest, timely notification is worth more than a vendor's reassurance.
Sources
This page is maintained by Ask Before You App. It is not legal advice. Districts should consult their own counsel for compliance and notification decisions. Questions: [email protected].