Edtech company settles with FTC in wake of data breach
好的,我现在要帮用户总结这篇文章的内容。用户的要求是用中文,控制在100个字以内,不需要特定的开头,直接写描述。 首先,我快速浏览文章。文章讲的是一个教育科技公司Illuminate Education和美国联邦贸易委员会(FTC)达成协议,解决数据泄露的问题。2021年12月发生了大规模的数据泄露,影响了超过1000万学生。泄露的原因包括网络安全性差、员工离职后账户未及时处理、数据存储不加密等。公司之前向客户承诺了高标准的数据保护措施,但实际上并没有做到。 接下来,我需要提取关键信息:公司名称、事件时间、受影响人数、泄露原因、解决方案以及监管机构的措施。然后将这些信息浓缩成一句话,确保不超过100字。 可能的结构是:公司名称 + 事件 + 原因 + 解决方案 + 监管机构的措施。例如:“教育科技公司Illuminate因2021年数据泄露被指控安全措施不足,同意删除多余数据并实施安全计划。” 检查字数是否符合要求,并确保信息准确无误。最后确认没有使用“文章内容总结”之类的开头,直接描述事件。 </think> 教育科技公司Illuminate因2021年数据泄露被指控安全措施不足,同意删除多余数据并实施安全计划。 2025-12-1 19:46:11 Author: therecord.media(查看原文) 阅读量:7 收藏

An educational technology provider has agreed to implement a data security program and delete unnecessary data to settle allegations that poor security practices led to a massive 2021 data breach.

The Federal Trade Commission (FTC) on Monday announced the agreement with Wisconsin-based Illuminate Education. The agency alleges that Illuminate told customers it protected their data but in reality had shoddy network security, leading to the breach of personal data belonging to 10.1 million students in December 2021. 

A hacker used credentials belonging to a former employee to breach Illuminate’s database, which was stored on a third-party cloud provider, the FTC said. The former employee had left the company three and a half years before the credentials were used, according to the agency.

Data accessed by the hacker included email and mailing addresses, dates of birth, student records and health information, the FTC said.

Illuminate said on its website that it safeguards “your data like it’s our own” and that it takes “security measures—physical, electronic, and procedural—to help defend against the unauthorized access and disclosure of your information.”

Contracts with school systems misrepresented the company’s security practices by falsely claiming student data was encrypted, according to the FTC.

A third-party vendor allegedly notified Illuminate that its network was vulnerable to hacking in January 2020, but the company did not address the problems, the FTC said. The security deficiencies included “failing to implement reasonable access controls that safeguard students’ personal information, effective threat detection and response, and vulnerability monitoring and patch management practices,” the FTC said in a blog post.  

Illuminate also stored student data in plain text until at least January 2022, according to the agency.

The company waited nearly two years to tell some school districts about the breach, impacting more than 380,000 students who were unaware that their data had been hacked.

Illuminate has agreed to no longer deceive customers about its security protocols, alert school districts about breaches quickly and delete personal data that it no longer needs to provide services as part of the settlement agreement. 

The firm also has agreed to adhere to a publicly available data retention schedule that lays out deletion timeframes, establish a comprehensive information security program and notify the FTC if it has reported a data breach to another federal, state, or local government.

A spokesperson for Illuminate did not immediately respond to a request for comment.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Suzanne Smalley

Suzanne Smalley

is a reporter covering privacy, disinformation and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop and Reuters. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.


文章来源: https://therecord.media/illuminate-education-data-breach-settlement-ftc
如有侵权请联系:admin#unsafe.sh