Skip to content
Data breachResolved

Chegg data breach (2018)

The education-technology company Chegg disclosed a 2018 breach affecting about 40 million users, exposing emails, names and unsalted MD5 password hashes; the FTC later cited four breaches and ordered Chegg to overhaul its security.

Victim
Chegg
records
39.7M
users
40.0M

In April 2018, the U.S. education-technology company Chegg β€” known for textbook rentals, homework help and online tutoring β€” suffered a data breach affecting approximately 40 million registered users. Chegg disclosed the incident in a September 2018 SEC filing, and the breach later became the centerpiece of a 2022 Federal Trade Commission enforcement action that cited a pattern of repeated security failures.

What happened

An unauthorized party gained access to a Chegg company database around late April 2018. Chegg said it learned of the intrusion on 19 September 2018 and disclosed it days later in a Form 8-K, estimating that data on roughly 40 million active and inactive users had been accessed. The company initiated password resets for affected accounts.

What was exposed

The compromised records included names, email addresses, usernames, and passwords stored as unsalted MD5 hashes β€” a weak scheme highly vulnerable to cracking. A smaller subset of records also contained shipping addresses and phone numbers. Have I Been Pwned indexed 39,721,127 unique accounts from the dataset.

The FTC action

In October 2022, the FTC charged Chegg over its security practices, noting the company had suffered four separate breaches between 2017 and 2020. The complaint described basic failures: storing data without adequate encryption, lacking multi-factor authentication, providing no meaningful security training, and not adopting a written security policy until January 2021. The 2018 breach was tied to login credentials that gave broad database access; earlier incidents stemmed from phishing of employees.

The FTC noted the exposed data across these incidents went beyond logins β€” it included Social Security numbers, financial information, and, for some users, sensitive data such as religion, sexual orientation, disabilities and parents' income collected via a scholarship application service.

The order required Chegg to limit data collection, allow users to access and delete their data, and implement a comprehensive information-security program including multi-factor authentication and encryption.

Why it matters

Chegg became a high-profile example of regulatory consequences for chronic security neglect. The case showed that even an education brand handling vast amounts of sensitive student data could rely on unsalted MD5 and lack MFA for years. The FTC's order β€” emphasizing data minimization and mandatory MFA β€” set a template for how the agency would pursue companies whose breaches stemmed from foundational hygiene failures rather than sophisticated attacks.

Timeline

  1. An unauthorized party gains access to a Chegg company database containing user account data.

  2. Chegg learns of the unauthorized access to its database.

  3. Chegg discloses the breach in an SEC Form 8-K, estimating about 40 million users affected and forcing password resets.

  4. The FTC announces an action against Chegg, citing four data breaches between 2017 and 2020 and lax security practices.

  5. The FTC finalizes its order requiring Chegg to implement multi-factor authentication, encryption, data minimization and a comprehensive security program.

Sources

  1. haveibeenpwned.comhttps://haveibeenpwned.com/PwnedWebsites#Chegg
  2. ftc.govhttps://www.ftc.gov/news-events/news/press-releases/2022/10/ftc-takes-action-against-chegg-alleged-security-failures-exposed-data-employees-40-million-consumers
  3. sec.govhttps://www.sec.gov/Archives/edgar/data/0001364954/000136495418000187/cyrus.htm
  4. huntonprivacyblog.comhttps://www.huntonprivacyblog.com/2022/11/02/ftc-takes-action-against-chegg-for-alleged-security-failures-that-exposed-data-of-employees-and-40-million-consumers/
  5. idstrong.comhttps://www.idstrong.com/data-breaches/chegg-breach/

Related incidents

Data breachRansom paid

Instructure Canvas LMS ShinyHunters breach (2026)

ShinyHunters exploited Canvas's Free-For-Teacher account programme to exfiltrate 3.65 TB of data spanning approximately 275 million users across nearly 9,000 schools β€” names, email addresses, student IDs, and some private messages between students and teachers. Instructure reportedly paid the ransom and the data was destroyed.

Victim
Instructure (Canvas LMS)
Loss
$10.0M
Records
275.0M
Data breachResolved

Edmodo data breach (2017)

In May 2017, the education platform Edmodo was hacked resulting in the exposure of 77 million records comprised of over 43 million unique customer email addresses. The data was consequently published to a popular hacking forum and made freely available.

Victim
Edmodo
Records
43.4M
Data breachContained

Quora data breach

The question-and-answer platform Quora disclosed that an unauthorized third party had accessed the data of approximately 100 million users, including names, email addresses, salted-and-hashed passwords, and imported contact and demographic data.

Victim
Quora
Records
100.0M
Data breachResolved

Dubsmash data breach (2018)

The video-messaging app Dubsmash was breached in December 2018, exposing roughly 162 million accounts with email addresses, usernames and PBKDF2 password hashes that later surfaced for sale on the Dream Market dark-web bazaar via the broker GnosticPlayers.

Victim
Dubsmash
Records
161.7M