The Federal Trade Commission took action against Illuminate Education on December 1, 2025, after the Wisconsin-based company suffered a massive data breach that exposed personal information of more than 10 million students. In late December 2021, a hacker used login credentials from a former employee who had left the company three and a half years earlier.
The breach exposed students’ email addresses, home addresses, dates of birth, student records, and health information. The company had promised schools it would protect student data “like it’s our own” and claimed to use industry best practices. But the FTC found Illuminate failed to implement basic security measures, including storing student data in plain text format until at least January 2022.
Read more…
Source: ConsumerAffairs News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Singapore’s worst-ever data breach prompted the nation to bolster its cyber defences
October 26, 2020
In 2018, Singapore suffered its worst ever data breach when inadequate cybersecurity at SingHealth saw a quarter of the population’s medical records stolen. The subsequent official review recommended remedies that should already be basic security policies. Two years after the SingHealth hack, Singapore’s cybersecurity is being improved by everything from the fintech-oriented @-Wise Cybersecurity Centre of Excellence ...
- COVID-19 Vaccine-Maker Hit with Cyberattack, Data Breach
October 23, 2020
COVID-19 vaccine manufacturer Dr. Reddy’s Laboratories has shut down its plants in Brazil, India, Russia, the U.K. and the U.S. following a cyberattack, according to reports. The Indian company is the contractor for Russia’s “Sputinik V” COVID-19 vaccine, which is about to enter Phase 2 human trials. The Drug Control General of India (DCGI) gave the ...
- EU sanctions Russian hackers over 2015 German parliament attack
October 22, 2020
The Council of the European Union today announced sanctions imposed on Russian military intelligence officers part of the 85th Main Centre for Special Services (GTsSS) for their involvement in a 2015 hack of the German Federal Parliament (Deutscher Bundestag). EU’s sanctions include both travel bans and asset freezes and also block EU organizations and individuals from ...
- Russian state hackers stole data from US government networks
October 22, 2020
DHS Cybersecurity and Infrastructure Security Agency (CISA) and the FBI today warned that a Russian state-sponsored APT threat group known as Energetic Bear has hacked and stolen data from US government networks during the last two months. Energetic Bear (also tracked as Berserk Bear, TeamSpy, Dragonfly, Havex, Crouching Yeti, and Koala), a hacking group active since ...
- Data watchdog issues biggest ever fine over airline cyberattack
October 16, 2020
British Airways has been fined £20 million for “unacceptable” failures that led to personal details of hundreds of thousands of customers’ data being being stolen by hackers in 2018. The fine represents the largest financial penalty issued by the UK’s Information Commissioner’s Office (ICO) to date and is based on GDPR data protection regulation. The incident started ...
- Card details for 3 million Dickey’s customers posted on carding forum
October 15, 2020
The card details of more than three million customers of Dickey’s Barbecue Pit, the largest barbecue restaurant chain in the US, have been posted this week on a carding and fraud marketplace known as Joker’s Stash. The discovery was made by Gemini Advisory, a cyber-security firm that tracks financial fraud. “We worked with several partner financial institutions ...

