SEC, education company Pearson settle charges over 2018 security incident for $1 million
Full article735 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The company misled both the SEC and the public about the incident, the agency said.
British educational software company Pearson settled charges with the U.S. Securities and Exchange Commission for $1 million over it “misleading” handling of a 2018 data breach, the SEC announced Monday.
The SEC based its charges on a July, 2019 disclosure to the agency that a hypothetical “data privacy incident” could “result in a major data privacy or confidentiality breach” when the company had in fact already been breached and known about it for months, among other statements.
In its public response to the incident, which involved the theft of student information and administrator log-in accounts for 13,000 district, school and university customer accounts, Pearson also left out details about the extent of the stolen information, the SEC said.
Pearson claimed to have “strict protections” in place even though it had left a critical vulnerability unpatched for six months that the hackers exploited, along with other poor security practices cited by the SEC. It also failed to disclose that millions of rows of student data were involved in the incident.
It’s the second SEC settlement over a major data security issue in recent months, and a stiffer penalty than the nearly $500,000 it imposed on First American Financial over its exposure of more than 800 million document images. The Pearson incident raised questions about the protection of student privacy.
Last year, the Justice Department alleged that two suspected Chinese government-backed hackers, Li Xiaoyu and Dong Jiazhi, stole data from a host of U.S. targets in the medical and defense industry, but also from “an education company.” Pearson said it was that unnamed victim.
Pearson said it was “pleased” to resolve the issue with the SEC, and that the breached software, AIMSweb1.0, has been retired. It also said it appreciated the work of the FBI and DOJ to identify and charge the culprits.
“Protecting our customers’ information is of critical importance to us,” said a spokesperson, Tom Steiner. “Pearson continues to enhance its cyber security efforts to minimise the risk of cyberattacks in an ever-changing threat landscape.”
A judge last year dismissed a lawsuit against Pearson over the breach, saying the plaintiffs lacked standing.
More Scoops
Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket
Michele Spagnuolo allegedly placed multiple trades on the prediction marketplace, abusing internal access to Google’s nonpublic data on the most searched people in 2025.
SEC hits four companies with fines for misleading disclosures around SolarWinds hack
The long, bumpy road to cyber incident reporting legislation — and the one still ahead
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/sec-pearson-settlement-2018-data-breach/