FTC Action Hits Illuminate Education Over Massive Student Data Breach
2 December 2025 at 02:09
![]()
Why the Agency Intervened
FTC complaint outlines a series of allegations against the Wisconsin-based company, which provides cloud-based software tools for schools. According to the complaint, Illuminate Education claimed it used industry-standard practices to safeguard student information but failed to put in place basic security controls. The Illuminate Education data breach incident dates back to December 2021 when a hacker accessed the companyβs cloud databases using login credentials belonging to a former employee who had left the company more than three years earlier. This lapse allowed unauthorized access to data belonging to 10.1 million students, including email addresses, home addresses, dates of birth, academic records, and sensitive health information. FTC officials said the company ignored warnings as early as January 2020, when a third-party vendor alerted them to several vulnerabilities in their systems. The data security failures included weak access controls, gaps in threat detection, and a lack of proper vulnerability monitoring and patch management. The agency also noted that student data was stored in plain text until at least January 2022, increasing the severity of the breach.FTC Action: Requirements Under the Proposed Order
As part of the proposed settlement, the FTC will require Illuminate Education to adopt a comprehensive information security program and follow stricter privacy obligations. The proposed FTC order includes several mandatory steps:- Deleting any personal information that is no longer required for service delivery.
- Following a transparent, publicly available data retention schedule that explains why data is collected and when it will be deleted.
- Implementing a detailed information security program to protect the confidentiality and integrity of personal information.
- Notifying the FTC when the company reports a data breach to any federal, state, or local authority.