Illuminate Education, an educational technology company, has agreed to pay a $5.1 million fine and implement significant security reforms after a 2021 data breach exposed sensitive student information across 49 states, including three million students in California. The breach was attributed to multiple security failures, such as not deleting former employee credentials, inadequate monitoring for suspicious activity, and storing backup and active databases together, which allowed attackers to compromise both. The exposed data included student names, races, coded medical conditions, and special education accommodations. The settlement, announced by the attorneys general of California, Connecticut, and New York, also requires Illuminate to strengthen its access controls, improve account management, and enhance real-time monitoring.
The incident has raised broader concerns about data privacy and security practices in the edtech sector, as highlighted by school administrators struggling to confirm data deletion after ending contracts with vendors. The case underscores the risks posed by insufficient offboarding processes and the importance of robust vendor management to protect student and parent information. Illuminate was also accused of making misleading statements in its privacy policy regarding compliance with federal and state laws, further intensifying scrutiny of edtech companies' data protection commitments.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
California Attorney General Rob Bonta announced a $5.1 million settlement with Illuminate Education over the 2021 breach and the company's inadequate data security practices. The action also required the company to strengthen its security program and data-handling practices.
In 2021, ed-tech company Illuminate Education experienced a breach tied to poor security practices. Reporting indicates the incident exposed sensitive data relating to students and staff, forming the basis for later regulatory action.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcescworld.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.