Chegg data breach (2018)
The education-technology company Chegg disclosed a 2018 breach affecting about 40 million users, exposing emails, names and unsalted MD5 password hashes; the FTC later cited four breaches and ordered Chegg to overhaul its security.
- Victim
- Chegg
- records
- 39.7M
- users
- 40.0M
In April 2018, the U.S. education-technology company Chegg β known for textbook rentals, homework help and online tutoring β suffered a data breach affecting approximately 40 million registered users. Chegg disclosed the incident in a September 2018 SEC filing, and the breach later became the centerpiece of a 2022 Federal Trade Commission enforcement action that cited a pattern of repeated security failures.
What happened
An unauthorized party gained access to a Chegg company database around late April 2018. Chegg said it learned of the intrusion on 19 September 2018 and disclosed it days later in a Form 8-K, estimating that data on roughly 40 million active and inactive users had been accessed. The company initiated password resets for affected accounts.
What was exposed
The compromised records included names, email addresses, usernames, and passwords stored as unsalted MD5 hashes β a weak scheme highly vulnerable to cracking. A smaller subset of records also contained shipping addresses and phone numbers. Have I Been Pwned indexed 39,721,127 unique accounts from the dataset.
The FTC action
In October 2022, the FTC charged Chegg over its security practices, noting the company had suffered four separate breaches between 2017 and 2020. The complaint described basic failures: storing data without adequate encryption, lacking multi-factor authentication, providing no meaningful security training, and not adopting a written security policy until January 2021. The 2018 breach was tied to login credentials that gave broad database access; earlier incidents stemmed from phishing of employees.
The FTC noted the exposed data across these incidents went beyond logins β it included Social Security numbers, financial information, and, for some users, sensitive data such as religion, sexual orientation, disabilities and parents' income collected via a scholarship application service.
The order required Chegg to limit data collection, allow users to access and delete their data, and implement a comprehensive information-security program including multi-factor authentication and encryption.
Why it matters
Chegg became a high-profile example of regulatory consequences for chronic security neglect. The case showed that even an education brand handling vast amounts of sensitive student data could rely on unsalted MD5 and lack MFA for years. The FTC's order β emphasizing data minimization and mandatory MFA β set a template for how the agency would pursue companies whose breaches stemmed from foundational hygiene failures rather than sophisticated attacks.
Timeline
An unauthorized party gains access to a Chegg company database containing user account data.
Chegg learns of the unauthorized access to its database.
Chegg discloses the breach in an SEC Form 8-K, estimating about 40 million users affected and forcing password resets.
The FTC announces an action against Chegg, citing four data breaches between 2017 and 2020 and lax security practices.
The FTC finalizes its order requiring Chegg to implement multi-factor authentication, encryption, data minimization and a comprehensive security program.
Sources
- haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#Chegg
- ftc.govhttps://www.ftc.gov/news-events/news/press-releases/2022/10/ftc-takes-action-against-chegg-alleged-security-failures-exposed-data-employees-40-million-consumers
- sec.govhttps://www.sec.gov/Archives/edgar/data/0001364954/000136495418000187/cyrus.htm
- huntonprivacyblog.comhttps://www.huntonprivacyblog.com/2022/11/02/ftc-takes-action-against-chegg-for-alleged-security-failures-that-exposed-data-of-employees-and-40-million-consumers/
- idstrong.comhttps://www.idstrong.com/data-breaches/chegg-breach/