Skip to content
MarketScale
‹ Back to IndustriesSoftware & Technology

Chegg Inc. and the FTC’s Order Against Them Is a Wake-up Call for Data Privacy Strategy

The FTC’s order against Chegg is a wake-up call for businesses everywhere and their current data privacy strategy. Chegg Inc. (“Chegg”) has been punished by the Federal Trade Commission (FTC) for its “careless” cybersecurity practices that exposed the sensitive personal information of its customers and employees. Chegg, according to the FTC’s complaint, stored customer…

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By Software And Technology · CheggData BreachData PrivacyFtc
Share

Key takeaways

01

The FTC’s order against Chegg is a wake-up call for businesses everywhere and their current data privacy strategy.

02

(“Chegg”) has been punished by the Federal Trade Commission (FTC) for its “careless” cybersecurity practices that exposed the sensitive personal information of its customers and employees.

03

Chegg, according to the FTC’s complaint, stored customer…

Get featured

Want to get featured in MarketScale Software & Technology?

Create a free MarketScale workspace and get your company's expertise featured across our Software & Technology coverage. No credit card, no demo required.

Start free

The FTC’s order against Chegg is a wake-up call for businesses everywhere and their current data privacy strategy. Chegg Inc. (“Chegg”) has been punished by the Federal Trade Commission (FTC) for its “careless” cybersecurity practices that exposed the sensitive personal information of its customers and employees.

Chegg, according to the FTC’s complaint, stored customer data in plain text on its network. This data includes names, email addresses, Chegg usernames and passwords, shipping addresses, and answers to security questions. Employee information, such as names, Social Security numbers, bank account information, and driver’s license numbers, was also stored in plain text on Chegg’s servers. To top it off, Chegg stands accused of failing to secure its network properly, thus allowing a hacker to access Chegg’s network and steal private information.

According to the FTC, Chegg violated the Gramm-Leach-Bliley Act and the FTC Act by not securing its network and storing sensitive data plainly. As part of the settlement, Chegg will develop a comprehensive information security program and will obtain independent assessments of the program every two years. In addition, Chegg will be subject to FTC oversight for 20 years to come.

The FTC’s order against Chegg is a wake-up call, not only for educational technology companies in the education sector but also for school districts and schools public and private alike. The FTC order against Chegg was because of, as the FTC determined, failure to implement commercially reasonable security measures.

Sai Huda, CEO of CyberCatch, is a globally recognized risk and cybersecurity expert and author of the best-selling book “Next Level Cybersecurity.” He gives MarketScale his thoughts on why companies should pay attention to Chegg’s mistakes, and learn from them to ensure their business’s data stays private, but also, where Chegg went wrong, and how businesses can reform their strategies to meet commercially reasonable security measures.

Sai’s Thoughts:

“Chegg had multiple phishing attacks that were successful. Chegg had other deficiencies that attackers exploited to steal over 40 million students and consumers’ data, which included parents and finally, the FTC said Enough is enough. So the question is, what do commercially reasonable security measures mean when FTC describes them?

It is really complying with a standard such as NIST cybersecurity framework. There are 108 controls, and this is really what educational technology companies minimally must implement and comply with, but also school districts and schools public and private alike should really implement those 108 controls.

These controls are prevention, detection, and response. That is an adequate defense and that will enable schools or even technology companies to be able to make the assertion that it has implemented commercial and reasonable security measures.

Your experts belong here

Every story in MarketScale Software & Technology starts with a company putting its solutions engineers, product teams, and customer engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Buyers ask AI engines who to consider, and published expert answers are what those engines cite.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

SA
Software And Technology

Follow Software & Technology Insights

Get new expert content in your inbox.

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. Explore how your experts, customers, and partners can become useful content for buyers and AI search.

Free plan

You just read one Software & Technology expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your solutions engineers, product teams, and customer engineers into the articles, video, and social content Software & Technology buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale workspace, up to 10 people
One professional video edit a month for qualifying companies
Media requests to your crowd, remote recording, AI writing tools
$0, no credit card, nothing that expires

More Software & Technology Insights

Nvidia CEO Jensen Huang Says Chip Sales Could Double Next Year—If the Supply Chain Can Keep Up

Nvidia CEO Jensen Huang Says Chip Sales Could Double Next Year—If the Supply Chain Can Keep Up

Nvidia CEO Jensen Huang forecasted doubling chip sales next year, but the company's CFO frames this as the supply-unconstrained scenario, signaling that supply chain capacity—not demand—is the real constraint. Nvidia and Palantir announced a collaboration to apply AI to Nvidia's own supply chain operations to identify bottlenecks and allocate materials more effectively.

  • 01Nvidia's doubling forecast depends on supply chain throughput, not demand—the company itself is supply constrained according to CFO Colette Kress.
  • 02Nvidia and Palantir said their first sovereign AI deployment for Nvidia’s operations is designed to spot supply constraints earlier and improve how materials are allocated across production.
  • 03Enterprise buyers should plan for competitive allocation pressure, higher networking and infrastructure costs alongside GPU spending, and the emergence of on-premises architectures as first-class options.

Sep 20, 2026

Fifth Third, Priority and CSI deals put a premium on payments built into software

Fifth Third, Priority and CSI deals put a premium on payments built into software

Fifth Third led a strategic investment in Payload, Priority Commerce agreed to acquire IntelliPay, and CSI acquired Qolo in a series of summer transactions, PYMNTS reported. Together, the deals point to buyers valuing payments technology already integrated into the software customers use, not just standalone processing capacity. For operators, that means the entity holding payment data can change hands without the front-end software changing.

  • 01BCG says SaaS providers with integrated payments accounted for 36% of small and midsize business acquiring revenue in 2024 and projects that share will reach 45% by 2028.
  • 02Finance and IT leaders using property, practice management or utility billing platforms should reread payments and data clauses, since the entity holding payment data can change hands even if the software front end does not.

Sep 19, 2026

System integrators shape whether factory tech pays off, Smart Industry argues

System integrators shape whether factory tech pays off, Smart Industry argues

Smart Industry’s Sept. 9, 2026 piece argues plant technology creates no business value until system integrators fit it into existing systems, operations and workflows. Related summer coverage highlights upskilling, institutional knowledge and technician demand alongside the same integration-and-deployment theme. The framing shifts attention from which platform to buy to who implements it and how the engagement is scoped.

  • 01Smart Industry's framing moves the buying question from which platform to license to who integrates it and how that engagement is scoped, which puts the system integrator line item at the center of the return rather than in implementation overhead.
  • 02Gartner figures cited by Quality Magazine show 24% of industrial enterprises using IoT have implemented digital twins and 42% plan to, suggesting most IoT-using plants still have digital twin integration work ahead.
  • 03The Deloitte and Manufacturing Institute report, as covered by Smart Industry, says AI can embed skills into workflows to address technician demand; the sharper question for a plant manager is whether that changes headcount or changes what each technician can cover.

Sep 18, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

SA
Software And Technology

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Software & Technology and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512