Back K12Dive Illuminate Education reaches settlement with FTC over 2021 data breach | K
The FTC alleged the ed tech company knew of multiple security vulnerabilities a year before a breach exposed 10 million students’ personal information.
Data exposed by Illuminate’s 2021 breach included students’ email and mailing addresses, dates of birth, school records and health-related information, according to the FTC's complaint. The commission added that some of the issues flagged to Illuminate in its third-party cybersecurity assessments included a lack of controls for who had access to students' information and a failure to encrypt student data.
Moreover, the FTC said Illuminate didn’t notify some affected districts — representing a collective 380,000 students — for almost two years after the incident, the commission alleged.
The breach impacted some of the nation’s largest school systems, including New York City Public Schools and Los Angeles Unified School District .
Under the FTC’s proposed order, Illuminate would have to:
“Illuminate pledged to secure and protect personal information children and failed to do so,” said Christopher Mufarrige, director of the FTC’s Bureau of Consumer Protection, in a Monday statement. “Today’s action is an important reminder to companies that the FTC will hold them accountable if they fail to keep their privacy promises to consumers, particularly when it involves children’s medical diagnoses and other personal data.”
In 2022, Illuminate was acquired by another ed tech company, Renaissance .
In a statement emailed to K-12 Dive on Monday, an Illuminate spokesperson said Renaissance had incorporated Illuminate’s products “into its cybersecurity and data protections program, which includes robust security protocols and controls used to safeguard the integrity and confidentiality of the data entrusted to us by schools, educators, and families.”
The Illuminate data breach is not the most recent high-powered breach to affect the K-12 sector.
In January 2025, PowerSchool informed districts that it had fallen victim to a widespread breach that eventually impacted more than 60 million students and 10 million teachers. The hacker responsible for the incident — a 19-year-old college student — was recently sentenced to four years in prison and nearly $14.1 million in restitution.
Some state leaders have begun investigating PowerSchool due to that breach.
In September, for example, Texas filed a lawsuit against PowerSchool for allegedly failing to protect sensitive student and teacher data. According to Texas Attorney General Ken Paxton, the breach exposed the personal identifying and health information of more than 880,000 children and teachers in the state.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
