DisclosureLens
HackingTechnologyEducationInformationEmployee Data InvolvedIdentity (basic)Government IDMediumContained

CHEGG, INC.

bd_83a5a8d4b2a2787d · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 10, 2020

Filed

Apr 27, 2020

To disclose

17 days

Affected

700

Confidence

64%
Full breach record for CHEGG, INC.3 incidents on file

Chegg, Inc. notified the California Attorney General that an outside hacker illegally obtained employee information for approximately 700 current and former U.S. employees on or about April 9, 2020. The company discovered the incident on April 10, 2020. The compromised data included names and Social Security numbers. Chegg retained a third-party forensic firm, notified law enforcement, and is offering two years of free credit monitoring and identity theft protection through Experian.

California clockDiscovered Apr 10, 2020Notified Apr 28, 202018d CA 60-day OK17 days discovery → filing

Incident timeline

undetected · 1 days
discovery → filing · 17 days

Apr 9, 2020

Begins

Apr 10, 2020

Discovered

Apr 27, 2020

Filed

vs. sector median

16 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed700 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.