evidoria

← Back to browse

Good practice Imported

FTC Orders 10 Years of Security Audits After Illuminate Education's Breach of 10.1 Million Students' Data

United States of America · Washington · See the United States of America profile · See the Washington profile

Top 100% 7/100 · Ask Evidence Copilot about this practice

The FTC's final order (5 June 2026) found K-12 software vendor Illuminate Education failed to secure data on 10.1 million students after a 2021-22 breach, and now requires biennial third-party security audits for 10 years plus data-minimisation and retention limits.

FTC Orders 10 Years of Security Audits After Illuminate Education's Breach of 10.1 Million Students' Data

Details

Promoter
U.S. Federal Trade Commission / Illuminate Education, Inc.
Period
Breach 2021-2022; FTC final order 5 June 2026
Keywords
K-12 education, edtech data privacy, regulatory enforcement

Description

Illuminate Education, Inc., a California-registered company whose cloud-based K-12 software has been used to manage information for more than 17 million students across over 5,200 U.S. school districts, suffered a data breach between late December 2021 and January 2022.
According to the U.S. Federal Trade Commission's complaint, a threat actor used a former employee's credentials to access Illuminate's cloud hosting environment and exfiltrated data — including students' email and mailing addresses, dates of birth, academic records and health-related information — undetected for about 13 days. The breach affected more than 10.1 million current and former students.
The FTC alleged Illuminate had ignored prior warnings about security vulnerabilities, failed to implement reasonable safeguards such as encryption, access controls and monitoring, misrepresented its data-protection practices in public statements and school-district contracts, and did not provide timely breach notifications.
The Commission's final consent order, issued 5 June 2026 after a public comment period, requires Illuminate to publish a data-retention schedule within 90 days, adopt data-minimisation practices, and undergo independent third-party security assessments at the outset and then every two years for ten years — one of the FTC's longest-running education-sector data-security orders to date.
This case is included as a cautionary example of governance failure: it shows the consequences of inadequate data protection in widely deployed education software and the kind of long-horizon regulatory remedy now being applied to the sector.

Read the full analysis: https://www.ftc.gov/legal-library/browse/cases-proceedings/222-3105-illuminate-education-inc-matter

Implementation

Implementation detail (cost, timeline, staffing, conditions for success) is not yet available for this practice.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful