Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Federal Trade Commission’s final order, announced January 26, 2023, requires Chegg to strengthen its information-security program, limit how it collects and keeps personal data, offer multifactor authentication or another authentication method, and let customers access or request deletion of their information. The FTC said four breaches between 2017 and 2020 exposed personal information; its estimate of about 40 million affected users and employees describes exposed records, not confirmed fraud victims.

What did the FTC order Chegg to do?

The FTC finalized an administrative consent order on January 26, 2023. It sets requirements for Chegg’s future handling and protection of information; it is distinct from the FTC’s allegations about past conduct. The agency’s final-order announcement and case page describe four central obligations:

  • Maintain a comprehensive information-security program. The order requires an ongoing program, not a one-time fix.
  • Limit personal-information collection and retention. Chegg must document what information it collects, why it needs it, and when it will delete it.
  • Offer multifactor authentication or another authentication method. The requirement covers customers and employees.
  • Give customers data access and deletion-request options. Customers must be able to access information Chegg collected about them and request its deletion.

The order addresses both organizational security controls and customer choices about their data. It does not name or endorse a particular security product.

How many Chegg data breaches did the FTC describe?

The FTC described four incidents from 2017 through 2020. In its January 2023 announcement, the agency said the breaches exposed personal information associated with about 40 million users and employees. That is the FTC’s estimate of the scope of exposed information, not a count of people confirmed to have experienced identity theft or fraud.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Period FTC’s account
September 2017 A phishing attack on employees exposed direct-deposit information, according to the FTC’s initial announcement.
2018 The FTC said a former contractor used shared login information to access a third-party cloud database associated with approximately 40 million customers. The agency said the database included names, email addresses and passwords, as well as sensitive scholarship-search information for some users.
2019–2020 The FTC described two further phishing incidents affecting employees and exposing sensitive employee information.

Information involved varied by incident and person. The FTC cited employee financial or medical information as well as customer account details; its account does not mean every affected individual had every listed field exposed. The FTC complaint and the agency’s announcements provide the incident details.

What security failures did the FTC allege?

In its administrative complaint, the FTC alleged that Chegg’s practices left personal information inadequately protected. These are allegations in the complaint, not a court’s findings on each underlying fact.

  • The FTC alleged that Chegg stored some sensitive information in plain text and used weak password-encryption practices through at least 2018.
  • The agency alleged inadequate access controls and monitoring, including problems related to shared credentials and the cloud database.
  • The complaint also alleged deficiencies in the company’s security policies and employee training.

The FTC announced the complaint and proposed consent order on October 31, 2022, then announced the final order in January 2023. The FTC explains in its initial release that a consent order issued on a final basis carries the force of law with respect to future actions. That procedural status should not be confused with a judicial determination that every complaint allegation was proven.

What does multifactor authentication mean here?

The order requires Chegg to offer multifactor authentication or another authentication method; it does not prescribe one specific tool. In general, multifactor authentication asks for an additional credential beyond a password or PIN. The FTC’s consumer guidance gives examples including a security key, a code sent by text or email, or an authenticator app. Those examples explain MFA generally and are not product recommendations or a list of tools mandated by the Chegg order.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What happened after the 2023 security order?

In September 2025, the FTC announced a separate action concerning Chegg’s subscription-cancellation practices and referenced the earlier security order. The agency’s September 15, 2025 announcement and case page concern that later matter, not an amendment to the 2023 data-security order. The case page was updated September 19, 2025 and listed the later matter as pending at that time; that dated status should not be read as a live update.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.