Consumers Affected
40,000,000
The FTC finalized an order against Chegg Inc. for failing to secure student data, leading to breaches that exposed personal information of about 40 million users and employees. Chegg must implement a comprehensive security program, limit data collection, offer multifactor authentication, and allow data access and deletion.
Chegg is required to implement a comprehensive information security program, limit the data it collects and retains, provide multifactor authentication to users, and allow users to request access to and deletion of their data.
In-house legal teams should review all vendor and customer agreements, particularly those with educational institutions or directly with students/parents, for clauses governing data security, breach notification, data minimization, and user rights. Specific clauses to scrutinize include data security requirements, encryption standards, password management, data retention and deletion policies, and provisions allowing user access or deletion requests. Given the order's focus on limiting data collection and offering multifactor authentication, contracts may need amendments to mandate MFA for account access, impose stricter data collection and retention limits, require robust encryption (including for stored data and passwords), and establish clear processes for user data access and deletion requests. Employment agreements handling employee personal and medical information should also be reviewed for adequate data protection safeguards.
Entity
Chegg Inc.
Also known as: Chegg
Industry
EducationOfficial Press Release
https://www.ftc.gov/news-events/news/press-releases/2023/01/ftc-finalizes-order-ed-tech-provider-chegg-lax-security-exposed-student-data
Chegg DecisionandOrder
https://www.ftc.gov/system/files/ftc_gov/pdf/Chegg-DecisionandOrder.pdf
ftc brings action against ed tech provider chegg careless se
https://www.ftc.gov/news-events/news/press-releases/2022/10/ftc-brings-action-against-ed-tech-provider-chegg-careless-security-exposed-personal-data-millions
Federal Trade Commission Enforcement Page
https://www.ftc.gov/enforcement
"Chegg Inc."
"careless data security practices"
"Exposed Student Data"
"medical information about Chegg employees"
"about 40 million users and employees"
$12.0M
The FTC alleged that payment processor Humboldt Merchant Services knowingly processed payments for more than 1,000 shell merchant entities serving as fronts for fraudulent companies engaged in unauthorized billing scams, despite red flags including chargeback rates nearly 10 times higher than card-brand thresholds. Under the proposed stipulated order filed in the U.S. District Court for the Eastern District of Michigan, Humboldt will pay $12 million for consumer redress and is permanently banned from processing payments for merchants with a heightened risk of potential fraud.
$4.8M
The FTC charged Canada-based payment processor Nuvei Corporation and its subsidiaries with knowingly processing payments for fraudulent merchants, including more than $30 million in payments for the Reimage tech support scam from 2017 to 2023, as well as merchants making false earnings claims and impersonating government tax authorities. Under the stipulated order filed in the U.S. District Court for the District of Arizona, Nuvei will pay $4.85 million for consumer redress, is banned from serving tech support telemarketers, and must implement robust merchant screening and chargeback monitoring practices. Note: this is a payments-fraud facilitation action under the FTC Act and Telemarketing Sales Rule, not a data privacy violation.
The FTC announced a seven-day extension of the public comment period on its proposed enforcement policy statement regarding personalized pricing, pushing the deadline from Sept. 18, 2026 to Sept. 25, 2026. Personalized pricing refers to using personal data to set prices based on what the company believes an individual consumer is willing to spend. This is a procedural announcement about draft agency guidance, not an enforcement action against any company, and no entity was named, no violation found, and no penalty imposed.
Colorado Attorney General Phil Weiser joined the FTC and 22 state attorneys general in filing a lawsuit against Amazon for manipulating the auctions used to set advertising prices, replacing actual auction results with higher prices since 2019 and overcharging nearly 1.2 million U.S. advertising customers. The FTC estimates total improper surcharges from 2018 to 2026 exceed $20 billion, with costs ultimately passed to shoppers through higher prices. The states seek a permanent injunction and monetary relief; no penalty has been imposed yet as this is a newly filed complaint.
$930K
The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.
The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.