The Chronicle of Higher Education, Inc. disclosed that unauthorized parties exploited a server vulnerability to obtain administrative credentials and accessed a database containing hashed and salted passwords for online accounts on February 17, 2020. The incident was discovered on May 10, 2020, after an internal alert. The company took the server offline, engaged forensic investigators, and notified law enforcement. Affected users were prompted to change passwords, and the company implemented stronger hashing technology and replaced the affected server.