Chegg
Disclosed Sep 26, 20188 years ago40,000,000 affectedSettled
Four breaches from 2017 to 2020 exposed 40M users' data; FTC order
A former contractor used a shared, fully privileged AWS access key to take 40 million Chegg user records in 2018, and three phishing breaches exposed more customer and employee data including financial, medical and Social Security information. The FTC's 2022 order requires a security program and data minimization.
What is known
| People affected | 40,000,000 (as reported by the organization) |
|---|---|
| Disclosed | Sep 26, 2018 |
| Happened | Apr 28, 2018 |
| Attack | Hacking |
| Data exposed | Emails, Names, Passwords, Phone numbers, Addresses, Financial, Health, Social Security numbers |
| Sector | Education · US |
| Status | Settled |
| Lawsuit or fine | FTC consent order (Oct 2022); no monetary penalty |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Cheggoag.ca.gov · Official notice | Official notice |
| Have I Been Pwned: Chegghaveibeenpwned.com · Aggregator | Aggregator |
| Chegg resets 40 million user passwords after data breachtechcrunch.com · News | News |
| FTC schools edtech giant Chegg over careless cybersecurity practicestechcrunch.com · News | News |
| Maine Attorney General breach notice archive: Cheggmaine.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Sep 26, 2018 | |
| Researchtotal | Sep 26, 2018 | 40,000,000 |
| Maine AGresidents of ME | Sep 26, 2018 | 75,000 |
| Have I Been Pwnedaccounts in the data | Aug 16, 2019 | 39,721,127 |
Other breaches at Chegg
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Apr 27, 2020Apr 27, 20206 years ago | Apr 27, 20206 years ago | Not stated | Other | Confirmed | Unknown |
History of this record
- 2026-09-25 · source: empty to https://www.maine.gov/ag/sites/maine.gov.ag/files/docs/Data%20breach%20spreadsheet%208-1-2021%20through%2012-5-2018%20REDACTED.xlsx · backfill source
- 2026-09-25 · status: confirmed to settled · seed source
- 2026-09-25 · lawsuit: empty to FTC consent order (Oct 2022); no monetary penalty · seed source
- 2026-09-25 · sector: tech to education · seed source
- 2026-09-25 · attack: unknown to hacking · seed source
- 2026-09-25 · data_types: ["emails","names","passwords","phone","addresses"] to ["emails","names","passwords","phone","addresses","financial","health","ssn"] · seed source
- 2026-09-25 · records_basis: hibp to organization · seed source
- 2026-09-25 · records: 39721127 to 40000000 · seed source
- 2026-09-25 · summary: In April 2018, the textbook rental service Chegg suffered a data breach that impacted 40 million subscribers. The exposed data included email addresses, usernames, names and passwords stored as unsalted MD5 hashes. A small number of records to A former contractor used a shared, fully privileged AWS access key to take 40 million Chegg user records in 2018, and three phishing breaches exposed more customer and employee data including financial, medical and Social Security informati · seed source
- 2026-09-25 · title: empty to Four breaches from 2017 to 2020 exposed 40M users' data; FTC order · seed source
- 2026-09-25 · hibp: empty to Chegg · backfill source
- 2026-09-25 · sector: other to tech · backfill source
- 2026-09-25 · data_types: [] to ["emails","names","passwords","phone","addresses"] · backfill source
- 2026-09-25 · records_basis: empty to hibp · backfill source
- 2026-09-25 · records: empty to 39721127 · backfill source
- 2026-09-25 · occurred: empty to 2018-04-28 · backfill source
- 2026-09-25 · summary: empty to In April 2018, the textbook rental service Chegg suffered a data breach that impacted 40 million subscribers. The exposed data included email addresses, usernames, names and passwords stored as unsalted MD5 hashes. A small number of records · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.