Breach report
EducationChegg
Chegg resets 40 million user passwords after data breach
Education technology company Chegg disclosed in September 2018 that an intruder had accessed a database holding names, emails, shipping addresses and hashed passwords for about 40 million users, prompting a platform-wide password reset.
Reported by TechCrunch
Records exposed
40M
About 40 million users
Scale vs. largest on file
- When
- 2018
- How they got in
- Unauthorized access to a company database
- Sector
- Education
On September 25, 2018, Chegg, the Santa Clara-based company known for textbook rentals and online homework help, disclosed in a filing with the Securities and Exchange Commission that an unauthorized party had accessed one of its databases. The intrusion had occurred on or around April 29, 2018, but Chegg said it did not discover it until September 19, nearly five months later. The company estimated that about 40 million customers were affected.
The database contained user data for Chegg.com and some of its affiliated services, including names, email addresses, shipping addresses, usernames and hashed passwords. Chegg said it had found no evidence that financial information or Social Security numbers were accessed. The company did not detail how the attacker gained entry.
Chegg began resetting passwords for all users across its platform, including its EasyBib citation tool and other subsidiary brands, and notified law enforcement. Its stock fell by more than 10 percent after the disclosure. Because many of Chegg's users were high school and college students, security experts warned that the stolen credentials could be reused against university and personal email accounts.
The 2018 incident turned out to be one of four data security lapses at Chegg over several years. In 2022, the Federal Trade Commission took action against the company, alleging that it had failed to protect sensitive information about students and employees, including through the 2018 breach, in which the agency said a former contractor had used login credentials shared among employees to access cloud storage. The FTC also said Chegg stored passwords using an outdated hashing method. The resulting order required Chegg to limit the data it collects and retains, offer users multi-factor authentication, allow customers to request deletion of their data, and implement a comprehensive information security program.
The Chegg case showed how education technology companies accumulate large volumes of data on young people and how slow detection can leave that information exposed for months. The FTC's order was notable for requiring data minimization and multi-factor authentication, measures that have since become standard expectations in regulatory settlements. For students, it was an early lesson in the risks of password reuse across academic and personal accounts.