Dwelling › Privateness
FTC Orders Chegg to Enhance Safety Following A number of Knowledge Breaches
By Ionut Arghire on November 01, 2022
Tweet
The Federal Commerce Fee (FTC) this week introduced that it has reached an settlement with training expertise supplier Chegg over the corporate’s cybersecurity failures resulting in a number of information breaches.
The Santa Clara, California-based firm offers pupil companies equivalent to on-line tutoring and digital and bodily textbook leases to highschool and faculty college students.
The safety mishaps, the FTC says, have uncovered the private data of tens of hundreds of thousands of consumers and staff to cyberattacks, together with their Social Safety numbers, e mail addresses, and login data.
Since 2017, Chegg allegedly skilled 4 safety breaches, however the firm didn’t implement the mandatory protections.
The FTC is now requiring the corporate to enhance its safety stance, to gather much less private information than earlier than, to permit customers to entry and erase their information, and to implement multi-factor authentication (MFA).
In its criticism, the FTC alleges that Chegg didn’t hold the private data of each prospects and staff secure, together with delicate data equivalent to monetary information, medical data, delivery dates, sexual orientation, disabilities, and extra.
In September 2017, a Chegg worker fell for a phishing assault, resulting in the publicity of staff’ direct deposit data.
Lower than a yr later, a third-party cloud database containing the private data of roughly 40 million Chegg prospects was accessed by a former contractor, utilizing login credentials the corporate had shared each inside and outdoors the group.
The incident resulted within the compromise of names, e mail addresses, delivery dates, passwords, and delicate scholarship data (mother and father’ revenue vary, disabilities, and sexual orientation). Among the information was later discovered on the market on-line.
By 2020, Chegg skilled two further information breaches as results of phishing assaults, which led to the compromise of delicate worker information, together with medical and monetary data.
The FTC alleges that Chegg didn’t implement primary safety measures to guard the collected and saved data, saved information insecurely, and didn’t implement sufficient safety insurance policies and safety coaching for workers and contractors.
The FTC is requiring Chegg to element and restrict its information assortment practices, to supply shoppers with entry to their information, together with permitting them to request the deletion of the information, to implement MFA or the same authentication technique, and to implement a complete data safety program to cope with the lax safety practices.
SecurityWeek has emailed Chegg for a touch upon the settlement and can replace the article as quickly as a reply arrives.
Associated: Chegg Informs Workers of Knowledge Breach
Associated: FTC Targets Drizly and Its CEO Over Cybersecurity Failures That Led to Knowledge Breach
Associated: FTC Guidelines to Corral Tech Companies’ Knowledge Assortment
Get the Every day Briefing
- Most Current
- Most Learn
- Microsoft Patches Azure Cosmos DB Flaw Resulting in Distant Code Execution
- Anxiously Awaited OpenSSL Vulnerability’s Severity Downgraded From Important to Excessive
- Tailoring Safety Coaching to Particular Sorts of Threats
- FTC Orders Chegg to Enhance Safety Following A number of Knowledge Breaches
- Mattress Bathtub & Past Investigating Knowledge Breach After Worker Falls for Phishing Assault
- US Gov Points Provide Chain Safety Steerage for Software program Suppliers
- Engineering Workstations Used as Preliminary Entry Vector in Many ICS/OT Assaults: Survey
- Musk Now Will get Likelihood to Defeat Twitter’s Many Pretend Accounts
- Bearer, Pocket book Labs, Protexxa Increase Hundreds of thousands in Seed Funding
- US Businesses Subject Steerage on Responding to DDoS Assaults
In search of Malware in All of the Mistaken Locations?
First Step For The Web’s subsequent 25 years: Including Safety to the DNS
Tattle Story: What Your Laptop Says About You
Be in a Place to Act By Cyber Situational Consciousness
Report Exhibits Closely Regulated Industries Letting Social Networking Apps Run Rampant
2010, A Nice Yr To Be a Scammer.
Do not Let DNS be Your Single Level of Failure
Tips on how to Establish Malware in a Blink
Defining and Debating Cyber Warfare
The 5 A’s that Make Cybercrime so Enticing
Tips on how to Defend Towards DDoS Assaults
Safety Budgets Not in Line with Threats
Anycast – Three Causes Why Your DNS Community Ought to Use It
The Evolution of the Prolonged Enterprise: Safety Methods for Ahead Pondering Organizations
Utilizing DNS Throughout the Prolonged Enterprise: It’s Dangerous Enterprise