FTC settlement requires Illuminate to delete unnecessary student data
ID: 0e7c5bc7-3539-5c72-8ea6-e4e4dab2b285
STIX ID: report--0e7c5bc7-3539-5c72-8ea6-e4e4dab2b285
Feed Name: Bleeping Computer
The FTC proposes requiring Illuminate Education to delete unnecessary student data and improve its security after a December 2021 breach in which attacker(s) used credentials from a former employee to access third-party cloud databases and exfiltrate data for about 10.1 million students (emails, addresses, DOBs, student records and health information). The agency found multiple security failures — lack of access controls, poor detection and response, weak vulnerability management, and storage of plaintext data — and criticized delayed notification and misrepresentations about encryption; the settlement mandates remediation, data-retention limits, truthful security claims, breach reporting to the FTC, and civil penalties for violations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
