The Federal Trade Commission (FTC) finalized a settlement with educational software provider Illuminate Education over a database breach that exposed the personal records of more than 10 million students. This enforcement action shows the cybersecurity risks schools face when they rely on third-party vendors to manage student information. As we previously reported regarding the Canvas LMS breach, school platforms are increasingly prime targets for hackers.
What Happened
According to the FTC press release, the breach occurred between December 2021 and January 2022 when a hacker accessed Illuminate’s cloud databases. The company, which provides software to track demographics, attendance, and student grades, failed to secure its student profiles. Compromised records included sensitive data such as names, dates of birth, academic scores, and special education needs. In some cases, the files listed disciplinary status, foster care placement, or homelessness.
The federal investigation revealed that Illuminate ignored basic security protocols. According to the final consent order, the company stored confidential student data in plaintext without encryption. A former employee's Amazon Web Services (AWS) credentials also remained active with full administrator privileges for more than three years after they left the company. Illuminate had also been warned about these vulnerabilities by a third-party security firm nearly two years before the hack but did not act.
The Bigger Picture
This case shows a systemic vulnerability in how the educational technology sector handles student privacy. A report by the UK Information Commissioner’s Office found widespread compliance gaps among 28 audited edtech providers, noting a lack of data minimization and "insufficiently detailed contracts with schools."
Under federal law in the United States, the Family Educational Rights and Privacy Act (FERPA) protects student education records. When schools outsource services to digital platforms, those third-party vendors act as "school officials" and are legally bound by the same FERPA compliance standards. Yet, many schools lack the technical expertise to audit their vendors’ security practices.
The FTC's ruling sets a strict precedent. Under the terms of the finalized order, Illuminate cannot misrepresent its data protection practices. The company must implement a comprehensive security program and delete inactive student profiles that are no longer necessary. It must also submit to independent security assessments every two years for the next decade.
What This Means for Families
When a school signs up for an educational platform, parents rarely have the option to opt out. Their children’s personal information is uploaded to the cloud automatically. If a breach occurs, the effects can persist for years. Exposed data like Social Security numbers, birth dates, and disciplinary records can lead to identity theft or academic discrimination.
Worse, Illuminate’s databases contained historical data of students who graduated years earlier. Keeping this "zombie data" by archiving profiles indefinitely leaves former students exposed long after they leave the school system.
What You Can Do
First, parents can demand data minimization policies. Ask your school board how long third-party edtech vendors are permitted to store student data, and demand that they mandate the immediate deletion of records for students who graduate or transfer.
Second, inquire about vendor audits. Ask school administrators if they require vendors to show proof of independent cybersecurity assessments, which are now standard under the FTC's enforcement guidelines.
Finally, exercise your FERPA rights. Parents have the legal right under federal guidelines to inspect and review any education records held by the school or its vendors, and to request corrections to inaccurate or sensitive demographic profiling.