Ed tech company fined $5.1 million for poor data security practices leading to hack
嗯,用户让我帮忙总结一下这篇文章的内容,控制在100字以内,而且不需要特定的开头。首先,我需要通读文章,抓住主要信息。 文章讲的是Illuminate Education公司因为安全措施不到位导致2021年的数据泄露事件。三个州的总检察长起诉了他们,公司同意支付510万美元的罚款,并进行业务整改。 接下来,数据泄露影响了49个州的学生,特别是加州有300万学生受影响。泄露的信息包括学生姓名、种族、医疗状况等敏感信息。 安全问题方面,公司没有删除前员工的登录凭证,导致黑客利用这些信息入侵系统。此外,公司也没有监控可疑活动,并且备份数据库和活动数据库没有分开,导致备份也被入侵。 公司还被指控隐私政策不实,声称符合法律要求。现在他们同意加强访问控制、实时监控,并分开存储数据库。 最后,三个州的总检察长共同提起诉讼,而公司尚未回应评论请求。 总结的时候要简洁明了,涵盖事件、罚款、影响范围、原因以及整改措施。确保在100字以内。 </think> 三州总检察长起诉教育科技公司Illuminate Education因2021年数据泄露事件致300万加州学生等隐私暴露。公司未删除前员工凭证、未监控异常活动及未分离备份数据库导致漏洞。将支付510万美元罚款并改进安全措施。 2025-11-6 21:16:6 Author: therecord.media(查看原文) 阅读量:28 收藏

Three state attorneys general announced Thursday that the educational technology company Illuminate Education will pay a $5.1 million fine and agree to make changes to its business to settle allegations that shoddy security practices led to a 2021 data breach.

The data breach exposed student names, races, coded medical conditions and whether they received special education accommodations. It impacted students in 49 states and three million in California alone.

Several security failings led to the breach, according to a press release from California Attorney General Rob Bonta.

For example, Illuminate allegedly failed to delete the login credentials of former employees, the press release said. The hacker who obtained the private data allegedly used a former Illuminate employee’s credentials to gain access to its network.

The ed tech firm also allegedly failed to monitor its systems for suspicious activity and did not separately secure backup and active databases. Because the databases were not separated, the press release said, the backup databases were also compromised when the active database was breached.

Illuminate also allegedly made false statements in its privacy policy, which told users its practices “meet or exceed the requirements of applicable federal and state law." 

The firm has agreed to bolster its access control and account management practices, do real time monitoring for suspicious activity and stop storing backup databases in the same network as active ones, the press release said.

Bonta brought the action alongside Connecticut Attorney General William Tong and New York Attorney General Letitia James.

Illuminate did not immediately respond to a request for comment.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/ed-tech-company-fined-5-million-data-breach-security-practices
如有侵权请联系:admin#unsafe.sh