ao link
Affino
Search Teiss
My Account
Remember Login
My Account
Remember Login

Illuminate Education fined $5.1 million over security failures that exposed student data

Educational technology company Illuminate Education will pay $5.1 million and implement new cybersecurity safeguards to settle allegations that inadequate data security practices led to a major 2021 breach compromising student information nationwide.


The settlement, announced Thursday by the attorneys general of California, Connecticut, and New York, resolves claims that the company’s security lapses exposed sensitive records belonging to millions of students, including names, races, coded medical information, and details on special education accommodations. The breach affected students in 49 states, with three million impacted in California alone.


Investigators found that several preventable failures contributed to the incident. Illuminate allegedly failed to revoke access credentials belonging to former employees, one of which was later used by a hacker to infiltrate the company’s systems. The company also lacked effective monitoring tools to detect suspicious activity and stored active and backup databases within the same network environment, allowing both to be compromised once the attacker gained access.


Authorities further determined that Illuminate’s privacy policy misrepresented its security posture, asserting that its practices “meet or exceed the requirements of applicable federal and state law,” despite the vulnerabilities identified.


Under the settlement, the company must enhance access control and account management procedures, conduct real-time monitoring for anomalous behavior, and maintain separate network environments for backup and active databases.


California Attorney General Rob Bonta, who led the action with Connecticut Attorney General William Tong and New York Attorney General Letitia James, said the agreement aims to ensure stronger protections for students’ personal data and greater accountability among educational technology providers handling sensitive information.


Illuminate Education, based in Irvine, California, has not issued a public response regarding the settlement or the breach.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Affino

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis Park, London, N3 1HF

23-29 Hendon Lane, London, N3 1RT

020 8349 4363

© 2025, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543