Data breach
Chegg
- Records
- 39,821,666
- Breach date
- 28 April 2018Estimated
- Added
- 1 December 2024
What was exposed
5 types of data · 1 puts you at serious risk
- Email addresses39,793,255
- Passwords30,133,297
- Usernames2,643,996
- Names833,566
- Home addresses14,768
About this breach
In April 2018, an unauthorized party gained access to a Chegg database holding user data for chegg.com and affiliated brands such as EasyBib. According to our investigation team, the breach indexed here contains roughly 39.8 million records. Chegg itself disclosed the incident in a filing to the Securities and Exchange Commission in September 2018, and the company's own filings later became part of a Federal Trade Commission enforcement action that described the intrusion in greater detail. According to the FTC complaint, a former contractor used shared AWS root credentials to copy a database holding personal information of approximately 40 million Chegg platform users.
Breach Timeline
Around April 29, 2018: An unauthorized party gained access to a Chegg database, per Chegg's SEC filing.
September 19, 2018: Chegg learned of the breach.
September 25, 2018: Chegg disclosed the incident in an 8-K filing to the SEC.
September 26, 2018: The company began notifying approximately 40 million active and inactive registered users and certain regulators, and initiated a password reset for all accounts.
What Information Was Compromised?
Our analysis found the following data types in this breach: 39,793,255 email addresses, 30,133,297 passwords, 2,643,996 nicknames, 833,566 names, and 14,768 home addresses.
Chegg's SEC filing said the information that may have been obtained could include a user's name, email address, shipping address, Chegg username, and hashed Chegg password. The company said at the time that no Social Security numbers or financial information such as credit card numbers or bank account details were obtained.
The FTC complaint adds detail about the password storage: passwords were hashed with MD5, a function the agency said had been deprecated by experts years before the breach. The FTC also stated that about 25 million of the exfiltrated passwords appeared in plain text in a file found in an online forum in September 2018, meaning the hashes had been cracked.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The most immediate risk is account compromise. Because a large share of the passwords were later cracked into plain text, anyone who used that Chegg password on other sites faces a credential stuffing risk, where attackers try the same email and password combination across other services. That is a particular concern for students, who may have reused a password across a school account and Chegg.
The email addresses and names in the breach also support targeted phishing, since messages can be made to look like legitimate Chegg or EasyBib communication. For the smaller group whose home addresses were included, the exposure adds a physical privacy risk. Some universities, including Miami University, later warned students and staff that credentials from the breach had surfaced on publicly accessible sources and urged password changes.
What Is Chegg Doing in Response?
After learning of the incident in September 2018, Chegg disclosed it to the SEC within about a week, began notifying users and regulators on September 26, 2018, and initiated a password reset process for all user accounts, according to the company's filing and reporting by CNBC. The company said its investigation, supported by third-party forensics, was ongoing.
In January 2023, the FTC issued a complaint against Chegg covering a series of breaches from 2017 to 2020, including this one. Under the resulting settlement, as summarized by the FTC, Chegg must offer users multifactor authentication options, put a comprehensive data security program in place, minimize the personal data it collects, and allow users to delete certain personal information.
What Should You Do If You Were Affected?
Change your Chegg password, and any other account where you used the same or a similar password.
Turn on multifactor authentication wherever it is offered, especially for email, school, and banking accounts.
Watch for phishing emails that reference Chegg, EasyBib, or textbook orders, and avoid clicking links in unexpected messages.
In the news
- Bass Berry & Sims, SEC Staff Comments on Chegg's Data Breach Disclosurebassberrysecuritieslawexchange.com (opens in a new tab)
- CNBC, Ed tech company Chegg plunges after disclosing data breachcnbc.com (opens in a new tab)
- EdWeek Market Brief, Education Company Chegg Acknowledges Data Breachmarketbrief.edweek.org (opens in a new tab)
- FTC Complaint, In the Matter of Chegg, Inc.ftc.gov (opens in a new tab)
- FTC Consumer Alert, Data breaches were missed learning opportunities for ed tech company
