HackingTechnologyEducationInformationCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICCREDENTIALSLowContained
CHEGG, INC.
bd_555a6f2b78e3057d · schema v1 · pii pii-v1
Full breach record for CHEGG, INC. →In September 2018, Chegg, Inc. discovered that on or around April 29, 2018, an unauthorized party accessed a database hosting user data for Chegg.com and its family of student services. Potentially compromised data included names, email addresses, shipping addresses, Chegg usernames, and hashed passwords. No financial information such as credit card numbers, bank account info, or SSNs was believed to have been obtained.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-140180
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 26, 2018
- Raw hash
- ed91445560bcecdbfe5c3d1761cf8456212c4173f95ec563909cde8cf795cb87
Reporting entity
- Name
- CHEGG, INC.norm: chegg
- Domain
- chegg.com
Victim entity
- Name
- CHEGG, INC.norm: chegg
- Domain
- chegg.com
- Industry
- TechnologyllmEducationllm
Incident
- Discovered
- Sep 19, 2018
- Materiality determined
- —
- Notification sent
- Sep 1, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage Object
- Threat actor
- External
- Regulator citations
- Notified California Office of the Attorney General
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.