CHEGG, INC.
ent_019de1ce102d11d4221cae116c741942
Disclosures
3
State AG · 2 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
700
nationwide · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CHEGG, INC.
- Normalized
- chegg— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300AKX7O8JG0O3G77
- SEC EDGAR CIK
- 0001364954
- Domain
- chegg.com
Disclosure history (3)newest first
- Massachusetts State AGas victim2020-05-06
Chegg, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-05-06. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2020-04-27
Chegg, Inc. notified the California Attorney General that an outside hacker illegally obtained employee information for approximately 700 current and former U.S. employees on or about April 9, 2020. The company discovered the incident on April 10, 2020. The compromised data included names and Social Security numbers. Chegg retained a third-party forensic firm, notified law enforcement, and is offering two years of free credit monitoring and identity theft protection through Experian.
- California State AGas victim2018-09-26
Chegg, Inc. disclosed that an unauthorized party gained access to a database hosting user data on or around April 29, 2018. The company discovered the incident on September 19, 2018. Affected data may include names, email addresses, shipping addresses, usernames, and hashed passwords. No financial information or SSNs were involved. Chegg engaged a third-party forensics firm and prompted users to change passwords.
Subsidiary disclosures (6)filed by group companies
◈ These filings were made by or about subsidiaries of CHEGG, INC. — not by CHEGG, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- California State AGvia Mathway LLC2020-05-22
Mathway LLC reported a data security incident where unauthorized parties acquired customer account data, specifically email addresses and hashed/salted passwords. The breach was discovered on May 15, 2024, following a tip. Mathway engaged cybersecurity specialists and law enforcement, required password changes, and implemented additional security measures. No credit card or subscription payment information was affected.
- Delaware State AGvia Mathway LLC2020-05-22
Mathway LLC notified users that customer account data, specifically email addresses and hashed/salted passwords, was acquired by an unauthorized party. The breach was confirmed on May 15, 2020, following a tip. Mathway engaged cybersecurity specialists and law enforcement, required password changes, and implemented additional security measures. No credit card or subscription data was affected.
- Oregon State AGvia Mathway LLC2020-05-22
Mathway LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2020-05-22. The breach was discovered on 5/15/2020. Notice was sent on 5/22/2020.
- Washington State AGvia Mathway LLC2020-05-22
Mathway, LLC notified the Washington AG that an unauthorized party acquired customer account data, specifically email addresses and hashed/salted passwords, affecting over 500 state residents. The breach was discovered on May 15, 2020, following a tip. Mathway engaged forensic investigators, coordinated with law enforcement, and required password resets for affected users.
- Illinois State AGvia Mathway LLC2020-01-01
MATHWAY LLC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-211). The register records the breach as discovered on May 15, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGvia Mathway LLC2020-01-01
MATHWAY LLC filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-210). The register records the breach as discovered on May 15, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.