The Federal Trade Commission (FTC) has taken enforcement action against Illuminate Education, an educational technology provider, following a significant data breach in December 2021 that exposed the personal information of over 10 million students. The breach occurred when a hacker exploited credentials belonging to a former employee who had left the company more than three years prior, gaining access to sensitive data such as email addresses, dates of birth, student records, and health information stored in cloud-based databases. The FTC alleged that Illuminate misrepresented its security practices to customers and school districts, including false claims about data encryption and inadequate access controls, threat detection, and vulnerability management.
As part of the settlement, Illuminate Education is required to implement a comprehensive data security program and delete unnecessary data. The company had previously settled with three state attorneys general for $5.1 million and agreed to a corrective action plan. The FTC emphasized that companies handling children's data will be held accountable for failing to uphold privacy and security commitments, especially when sensitive information like medical diagnoses is involved. Illuminate was also criticized for storing student data in plain text and for delayed notification to affected school districts about the breach.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
As part of the FTC settlement, Illuminate Education was required to delete personal data it no longer needed and limit future collection and retention of student information. The order also imposed broader safeguards for protecting student records.
The U.S. Federal Trade Commission announced a settlement with Illuminate Education, alleging the company failed to adequately secure students' personal data. The action required the company to address its security practices following the breach.
An intruder accessed Illuminate Education systems and stole data on roughly 10 million students, exposing personal information held by the edtech provider. The breach became the underlying incident that prompted later regulatory scrutiny.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.