TechNewsReel
Live

FTC Settles With Chegg Over Plain-Text Storage of Student Data

The settlement mandates strict security upgrades after the EdTech giant failed to encrypt sensitive user information.

TechNewsReel Newsroom · August 14, 2026

The Federal Trade Commission has reached a settlement with online education vendor Chegg, Inc. following data breaches that exposed sensitive student and user information. The enforcement action underscores a growing regulatory crackdown on EdTech providers that fail to secure the personal data of the students they serve.

According to the FTC complaint, Chegg stored critical customer data—including names, email addresses, and passwords—in plain text on its network. This lack of encryption left user credentials vulnerable to unauthorized access during the breaches. To resolve the matter, the settlement requires Chegg to implement comprehensive security measures, most notably the introduction of multifactor authentication (MFA) for its users. Additionally, the company must now adhere to strict data minimization protocols and provide users with explicit rights to access and delete their personal information.

The EdTech Security Gap

This incident occurs as the education sector continues a rapid shift toward digital platforms. Schools and universities increasingly rely on third-party vendors to manage learning management systems and supplemental study tools. However, this transition has often outpaced the implementation of robust security controls. Many EdTech providers have operated with legacy systems or insufficient safeguards, creating a systemic vulnerability where a single vendor breach can compromise the private data of millions of students across multiple institutions.

Implications for the Industry

The settlement serves as a definitive warning to the broader education technology market: the FTC will hold providers accountable for failing to implement reasonable security measures. By targeting the storage of passwords in plain text—a basic security failure—the commission is signaling that it will not tolerate negligence regarding student privacy. For other vendors, the case highlights that "reasonable security" now includes mandatory encryption and the provision of MFA, moving these features from optional enhancements to regulatory requirements.

Looking Ahead

Industry observers will now watch how Chegg implements these mandated security upgrades and whether other EdTech firms proactively audit their data storage practices to avoid similar FTC scrutiny. While the settlement addresses the immediate failures at Chegg, the broader question of how student data is shared and stored across the fragmented EdTech ecosystem remains a primary concern for privacy advocates and regulators alike.

Get a notification when a big story breaks. A few a day at most — no spam.