Chegg Inc. and the FTC’s Order Against Them Is a Wake-up Call for Data Privacy Strategy

 

The FTC’s order against Chegg is a wake-up call for businesses everywhere and their current data privacy strategy. Chegg Inc. (“Chegg”) has been punished by the Federal Trade Commission (FTC) for its “careless” cybersecurity practices that exposed the sensitive personal information of its customers and employees.

Chegg, according to the FTC’s complaint, stored customer data in plain text on its network. This data includes names, email addresses, Chegg usernames and passwords, shipping addresses, and answers to security questions. Employee information, such as names, Social Security numbers, bank account information, and driver’s license numbers, was also stored in plain text on Chegg’s servers. To top it off, Chegg stands accused of failing to secure its network properly, thus allowing a hacker to access Chegg’s network and steal private information.

According to the FTC, Chegg violated the Gramm-Leach-Bliley Act and the FTC Act by not securing its network and storing sensitive data plainly. As part of the settlement, Chegg will develop a comprehensive information security program and will obtain independent assessments of the program every two years. In addition, Chegg will be subject to FTC oversight for 20 years to come.

The FTC’s order against Chegg is a wake-up call, not only for educational technology companies in the education sector but also for school districts and schools public and private alike. The FTC order against Chegg was because of, as the FTC determined, failure to implement commercially reasonable security measures.

Sai Huda, CEO of CyberCatch, is a globally recognized risk and cybersecurity expert and author of the best-selling book “Next Level Cybersecurity.” He gives MarketScale his thoughts on why companies should pay attention to Chegg’s mistakes, and learn from them to ensure their business’s data stays private, but also, where Chegg went wrong, and how businesses can reform their strategies to meet commercially reasonable security measures.

Sai’s Thoughts:

“Chegg had multiple phishing attacks that were successful. Chegg had other deficiencies that attackers exploited to steal over 40 million students and consumers’ data, which included parents and finally, the FTC said Enough is enough. So the question is, what do commercially reasonable security measures mean when FTC describes them?

It is really complying with a standard such as NIST cybersecurity framework. There are 108 controls, and this is really what educational technology companies minimally must implement and comply with, but also school districts and schools public and private alike should really implement those 108 controls.

These controls are prevention, detection, and response. That is an adequate defense and that will enable schools or even technology companies to be able to make the assertion that it has implemented commercial and reasonable security measures.

Follow us on social media for the latest updates in B2B!

Image

Latest

radio
Where Experience Meets the Extreme: John F5VHQ at Radio’s Most Isolated Outpost
January 16, 2026

For some operators, Bouvet Island is the final frontier. For John (F5VHQ), it is a challenge that stands apart even after decades of DXpedition experience. A veteran of more than twenty years in the field and Vice President of the Clipperton DX Club, John joins the multinational 3Y0K team with both experience and conviction. Bouvet…

Read More
DX
Pursuing the World’s Rarest DX: Vadym Ivliev, UT6UD, and the Story That Led Him to Bouvet
January 16, 2026

For some operators, Bouvet Island represents the ultimate technical challenge. For Vadym Ivliev (UT6UD), it is something more personal—and more mysterious. From his home in Kyiv—far removed from the ice, storms, and isolation of Bouvet—Vadym has long been drawn to the island not only for its legendary radio silence, but for the stories it inspires….

Read More
GameStop
Inside GameStop’s Meteoric Stock Surge: A Former Executive Reflects on Power, Pivots, and the Price of Winning
January 15, 2026

The meme-stock era may feel like old news, but its aftershocks are still reshaping how leaders think about transformation, risk, and reward. In the wake of unprecedented short squeezes, shuttered storefronts, and sudden wealth creation, executives across retail and tech are still asking what actually happened—and why. Few episodes crystallize those questions better than…

Read More
podcast
The DisruptED Journey with Tim Maitland at MarketScale (Episode Three)
January 15, 2026

Storytelling is changing fast, shaped by new platforms, shifting audiences, and a growing demand for authenticity. What started as traditional podcasting has evolved into community-driven ecosystems built on real voices and lived experience. In this landscape, storytelling isn’t just content—it’s a way to build connection, spark engagement, and drive meaningful change. When done well,…

Read More