FTC settlement requires Illuminate to delete unnecessary student data

FTC settlement requires Illuminate to delete unnecessary student data

The Federal Trade Commission (FTC) is proposing that education technology provider Illuminate Education to delete unnecessary student data and improve its security to settle allegations related to an incident in 2021 that exposed info of 10 million students.

The agency’s decision comes shortly after the states of California, Connecticut, and New York agreed to settle their legal cases against Illuminate, related to the same incident, for $5.1 million.

Illuminate Education is a cloud-based technology product vendor for K-12 schools and school districts. 

Wiz

It offers a suite of tools to collect, organize, analyze, and report student data, covering academic performance, assessments, attendance, scheduling, and demographic and behavioral data.

Despite the heightened need to protect this data due to the sensitivity of the subjects, the FTC says the company has failed in its security program on multiple levels, including a lack of access controls, poor detection and response, weak vulnerability monitoring and patching practices, and plain-text storage.

Illuminate’s security failures were exposed in December 2021, when a hacker gained access to the company’s systems by using credentials from a former employee who had left the company more than three years before.

Using the credentials, the hacker accessed Illuminate’s databases, which were hosted on a third-party cloud provider, exfiltrating the personal data of approximately 10.1 million students, including: 

  • Email addresses
  • Physical addresses
  • Dates of birth
  • Student records
  • Health-related information

The FTC notes that Illuminate received warnings from a third-party vendor that its networks were riddled with security flaws. However, the company took no action to remediate them and even continued to store student data in plain text until January 2022.

The company also misrepresented its security stance and data protection measures to schools, claiming in contracts that “its practices and procedures are designed to meet or exceed private industry best practices,” and specifically mentioning data encryption as one of these measures.

The FTC says that Illuminate waited for two years after the incident to notify impacted school districts, leaving exposed users at risk of phishing and other attacks for an extended time period.

For these reasons, the agency will require the company to improve its defenses through a data security program to settle the allegations.

As part of the agreement, Illuminate will have to delete all unnecessary data, follow a public data-retention schedule, stop misrepresenting its security practices, and notify the FTC when reporting data breach incidents to other authorities.

The order is being finalized and will soon open for public comment for 30 days. Violations of the final order will incur a civil penalty of up to $51,744 per case.


tines

Break down IAM silos like Bitpanda, KnowBe4, and PathAI

Broken IAM isn’t just an IT problem – the impact ripples across your whole business.

This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what “good” IAM looks like, and a simple checklist for building a scalable strategy.

Read More
Bill Toulas

Latest

Embracer Follows Ubisoft In Splitting Off New Publisher To Handle Huge IP, Tomb Raider & LOTR Included

Say hello to Fellowship Entertainment by Ben Kerry 11 hours ago Embracer Group has today announced plans to create a secondary publishing label called Fellowship Entertainment, in order to "capture the full potential of the high-quality assets" that the group currently owns. The Swedish game publisher says that it hopes to spin off Fellowship Entertainment

Gwyneth Paltrow’s Daughter Apple Martin in Nancy Meyers Movie

Gwyneth Paltrow's Daughter Apple Martin Makes Directorial Debut With Student Show Apple Martin doesn’t fall far from the tree. Gwyneth Paltrow and Chris Martin ’s daughter will be following in her mom’s acting footsteps and making her movie debut in Nancy Meyers’ upcoming film, Deadline and Entertainment Weekly reported on May 18. The 22-year-old—who graduated

Lil Wayne speaks out after feeling overlooked by Coachella and the Grammys

Music Lil Wayne reacts to Coachell and Grammys snub Award-winning...

Newsletter

Don't miss

Embracer Follows Ubisoft In Splitting Off New Publisher To Handle Huge IP, Tomb Raider & LOTR Included

Say hello to Fellowship Entertainment by Ben Kerry 11 hours ago Embracer Group has today announced plans to create a secondary publishing label called Fellowship Entertainment, in order to "capture the full potential of the high-quality assets" that the group currently owns. The Swedish game publisher says that it hopes to spin off Fellowship Entertainment

Gwyneth Paltrow’s Daughter Apple Martin in Nancy Meyers Movie

Gwyneth Paltrow's Daughter Apple Martin Makes Directorial Debut With Student Show Apple Martin doesn’t fall far from the tree. Gwyneth Paltrow and Chris Martin ’s daughter will be following in her mom’s acting footsteps and making her movie debut in Nancy Meyers’ upcoming film, Deadline and Entertainment Weekly reported on May 18. The 22-year-old—who graduated

Lil Wayne speaks out after feeling overlooked by Coachella and the Grammys

Music Lil Wayne reacts to Coachell and Grammys snub Award-winning...

Kehlani at 30: How ‘Folded’ Changed Everything | Billboard Women In Music 2026

MusicBillboard Women in Music 2026 Impact Award recipient...

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand