Skip to content

Chegg

Disclosed Sep 26, 20188 years ago40,000,000 affectedSettled

Official notice

Four breaches from 2017 to 2020 exposed 40M users' data; FTC order

A former contractor used a shared, fully privileged AWS access key to take 40 million Chegg user records in 2018, and three phishing breaches exposed more customer and employee data including financial, medical and Social Security information. The FTC's 2022 order requires a security program and data minimization.

What is known

People affected40,000,000 (as reported by the organization)
DisclosedSep 26, 2018
HappenedApr 28, 2018
AttackHacking
Data exposedEmails, Names, Passwords, Phone numbers, Addresses, Financial, Health, Social Security numbers
SectorEducation · US
StatusSettled
Lawsuit or fineFTC consent order (Oct 2022); no monetary penalty
Check your emailHave I Been Pwned

Sources

Source
California Attorney General breach notice: Cheggoag.ca.gov · Official notice
Have I Been Pwned: Chegghaveibeenpwned.com · Aggregator
Chegg resets 40 million user passwords after data breachtechcrunch.com · News
FTC schools edtech giant Chegg over careless cybersecurity practicestechcrunch.com · News
Maine Attorney General breach notice archive: Cheggmaine.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CASep 26, 2018
ResearchtotalSep 26, 201840,000,000
Maine AGresidents of MESep 26, 201875,000
Have I Been Pwnedaccounts in the dataAug 16, 201939,721,127

Other breaches at Chegg

BreachAffected
Disclosed Apr 27, 2020Apr 27, 20206 years agoUnknown
History of this record
  • 2026-09-25 · source: empty to https://www.maine.gov/ag/sites/maine.gov.ag/files/docs/Data%20breach%20spreadsheet%208-1-2021%20through%2012-5-2018%20REDACTED.xlsx · backfill source
  • 2026-09-25 · status: confirmed to settled · seed source
  • 2026-09-25 · lawsuit: empty to FTC consent order (Oct 2022); no monetary penalty · seed source
  • 2026-09-25 · sector: tech to education · seed source
  • 2026-09-25 · attack: unknown to hacking · seed source
  • 2026-09-25 · data_types: ["emails","names","passwords","phone","addresses"] to ["emails","names","passwords","phone","addresses","financial","health","ssn"] · seed source
  • 2026-09-25 · records_basis: hibp to organization · seed source
  • 2026-09-25 · records: 39721127 to 40000000 · seed source
  • 2026-09-25 · summary: In April 2018, the textbook rental service Chegg suffered a data breach that impacted 40 million subscribers. The exposed data included email addresses, usernames, names and passwords stored as unsalted MD5 hashes. A small number of records to A former contractor used a shared, fully privileged AWS access key to take 40 million Chegg user records in 2018, and three phishing breaches exposed more customer and employee data including financial, medical and Social Security informati · seed source
  • 2026-09-25 · title: empty to Four breaches from 2017 to 2020 exposed 40M users' data; FTC order · seed source
  • 2026-09-25 · hibp: empty to Chegg · backfill source
  • 2026-09-25 · sector: other to tech · backfill source
  • 2026-09-25 · data_types: [] to ["emails","names","passwords","phone","addresses"] · backfill source
  • 2026-09-25 · records_basis: empty to hibp · backfill source
  • 2026-09-25 · records: empty to 39721127 · backfill source
  • 2026-09-25 · occurred: empty to 2018-04-28 · backfill source
  • 2026-09-25 · summary: empty to In April 2018, the textbook rental service Chegg suffered a data breach that impacted 40 million subscribers. The exposed data included email addresses, usernames, names and passwords stored as unsalted MD5 hashes. A small number of records · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Chegg

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.