ZeroHour
CyberScooppublished ()ingested @timstarks

SEC, education company Pearson settle charges over 2018 security incident for $1 million

criticalPolicy & legal exploited in the wildimportance 60
Full article735 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The company misled both the SEC and the public about the incident, the agency said.

(Getty Images)

British educational software company Pearson settled charges with the U.S. Securities and Exchange Commission for $1 million over it “misleading” handling of a 2018 data breach, the SEC announced Monday.

The SEC based its charges on a July, 2019 disclosure to the agency that a hypothetical “data privacy incident” could “result in a major data privacy or confidentiality breach” when the company had in fact already been breached and known about it for months, among other statements.

In its public response to the incident, which involved the theft of student information and administrator log-in accounts for 13,000 district, school and university customer accounts, Pearson also left out details about the extent of the stolen information, the SEC said.

Pearson claimed to have “strict protections” in place even though it had left a critical vulnerability unpatched for six months that the hackers exploited, along with other poor security practices cited by the SEC. It also failed to disclose that millions of rows of student data were involved in the incident.

It’s the second SEC settlement over a major data security issue in recent months, and a stiffer penalty than the nearly $500,000 it imposed on First American Financial over its exposure of more than 800 million document images. The Pearson incident raised questions about the protection of student privacy.

Last year, the Justice Department alleged that two suspected Chinese government-backed hackers, Li Xiaoyu and Dong Jiazhi, stole data from a host of U.S. targets in the medical and defense industry, but also from “an education company.” Pearson said it was that unnamed victim.

Pearson said it was “pleased” to resolve the issue with the SEC, and that the breached software, AIMSweb1.0, has been retired. It also said it appreciated the work of the FBI and DOJ to identify and charge the culprits.

“Protecting our customers’ information is of critical importance to us,” said a spokesperson, Tom Steiner. “Pearson continues to enhance its cyber security efforts to minimise the risk of cyberattacks in an ever-changing threat landscape.”

A judge last year dismissed a lawsuit against Pearson over the breach, saying the plaintiffs lacked standing.

More Scoops

The Polymarket prediction market platform logo appears on a smartphone placed on a reflective surface onto which a list of available bets is projected.
The Polymarket prediction market platform logo appears on a smartphone placed on a reflective surface onto which a list of available bets is projected, on March 9, 2026. (Photo by Samuel Boivin/NurPhoto via Getty Images)

Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket

Michele Spagnuolo allegedly placed multiple trades on the prediction marketplace, abusing internal access to Google’s nonpublic data on the most searched people in 2025.

(Photo by SUZANNE CORDEIRO / AFP) (Photo by SUZANNE CORDEIRO/AFP via Getty Images)

SEC hits four companies with fines for misleading disclosures around SolarWinds hack

threat landscape hearing
Sens. Gary Peters, D-Mich., and Rob Portman, R-Ohio, speak to Secretary of Homeland Security Alejandro Mayorkas, right, after a Senate Homeland Security and Governmental Affairs hearing Sept. 21, 2021 in Washington, D.C. (Photo by Greg Nash – Pool/Getty Images)

The long, bumpy road to cyber incident reporting legislation — and the one still ahead

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/sec-pearson-settlement-2018-data-breach/