Illuminate Education student-data incident

Unauthorized access to Illuminate's AWS-hosted IO Suite environment using a former employee's still-active privileged access key, followed by student-data exfiltration and destructive activity. Exfiltration of database backups containing current and former student information; fields varied by student and reporting population.

Last modified

Summary

  • Environment: System usernames and passwords alleged among the data in Illuminate's database backups; categories varied by individual.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: The three state settlements totaled $5.1 million, including $3.25 million to California and $1.7 million in New York penalties and costs, and imposed security, monitoring, retention, deletion, and incident-response obligations.
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to Illuminate’s AWS-hosted IO Suite environment using a former employee’s still-active privileged access key, followed by student-data exfiltration and destructive activity. [1][2][5]

Impact

Exfiltration of database backups containing current and former student information; fields varied by student and reporting population. [1][2][4]

Documented data types include:

  • Account credentials — System usernames and passwords alleged among the data in Illuminate’s database backups; categories varied by individual. [2][4][5]
  • Education records — Academic, behavior, enrollment, grade, course, and assessment information; categories varied by individual. [2][4][5]
  • Student identifiers — Student identification numbers; categories varied by individual and reporting population. [2][4][5]
  • Disability and special-education information — Accommodation, special-education, and disability information; categories varied by individual. [2][4][5]
  • Demographic information — Student demographic information; categories varied by individual and reporting population. [2][4][5]
  • Contact information — Mailing and email addresses alleged in the FTC complaint; categories varied by individual. [2][4][5]
  • Names — Student names; categories varied by individual and reporting population. [2][4][5]
  • Clinical information — Coded medical conditions and other health-related student information reported by regulators; categories varied by individual. [2][4][5]
  • Dates of birth — Dates of birth; categories varied by individual and reporting population. [2][4][5]

A cited record reports 1,700,000 individuals (Approximately 1.7 million current and former New York students in approximately 750 schools; jurisdiction-scoped and non-additive; as of 2025-11-05). [1][2][4]

A cited record reports 387,000 individuals (Nearly 387,000 current and former students newly identified in October 2023; a late-notification subset and not additive to the overall population; as of 2026-06-05). [1][2][4]

A cited record reports 434,000 individuals (More than 434,000 California students whose stolen information California characterized as sensitive; a subset of the California population and not additive; as of 2025-11-06). [1][2][4]

A cited record reports 3,000,000 individuals (California students impacted according to the California Department of Justice; jurisdiction-scoped and non-additive; as of 2025-11-06). [1][2][4]

A cited record reports 10,100,000 individuals (More than 10.1 million students according to the FTC complaint; regulator-alleged, not independently verified, and not additive to jurisdiction-specific populations; as of 2026-06-05). [1][2][4]

Timeline

  1. Activity began

    FTC complaint allegation for the date the threat actor gained access; disputed because Illuminate’s notice and New York findings place successful unauthorized database access on December 28.

    [2]
  2. Activity began

    Beginning of the successful unauthorized-access and database-acquisition window stated by Illuminate and the New York assurance; probing began on December 27.

    [1][5]
  3. Documented activity ended

    Date Illuminate says its cybersecurity response cut off further unauthorized access.

    [5]
  4. Discovery

    Date Illuminate’s data-security team discovered suspicious activity on systems storing customer data.

    [5]
  5. Activity began

    Beginning of the March 25–April 5, 2022 period in which Illuminate contacted initially identified New York schools and districts; not a universal notice date.

    [1]
  6. Documented event

    Date California, New York, and Connecticut announced their coordinated settlement actions.

    [4]
  7. Documented event

    Date the FTC issued its final complaint and final decision and order in docket C-4833.

    [3]
  8. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Attackers tried five sets of stolen AWS access keys and gained privileged access with a still-active IAM administrator key associated with a former employee who had left years earlier. [1]

The FTC complaint alleges the attacker demanded a ransom, Illuminate paid an undisclosed amount, not all stolen data was returned, and Illuminate could not verify deletion or whether copies were retained or shared. [2]

The FTC complaint alleges the attacker used the compromised administrator access to generate a token and create a new administrator-level user that could bypass the required multifactor-authentication flow. [2]

The FTC complaint alleges the attacker exfiltrated 787 SQL Server backups from Illuminate’s AWS environment. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

The three state settlements totaled $5.1 million, including $3.25 million to California and $1.7 million in New York penalties and costs, and imposed security, monitoring, retention, deletion, and incident-response obligations. The attacker modified security groups, reset database passwords, deleted database resources, and caused several Illuminate websites to become unavailable before access was terminated. NYAG and NYSED found that Illuminate failed to decommission inactive accounts, rotate credentials, limit privileges, encrypt student data at rest, monitor anomalous activity, timely remediate high-risk vulnerabilities, apply retention policies, and complete its initial incident analysis; Illuminate represented that it made post-incident improvements. The FTC complaint alleges initial notifications occurred from March through July 2022, while subsequent notifications to some districts, students, and parents occurred as late as October 2023. Illuminate’s Orange Unified supplemental notice states that the data for that notice population did not contain Social Security numbers, credit-card numbers, or bank-account numbers; this negative statement is not generalized to every affected population. The final FTC order prohibits specified privacy, security, and incident-notification misrepresentations; requires deletion and minimization of unnecessary covered information, a public retention schedule, a comprehensive security program, independent assessments, and reports to the FTC after certain government incident notifications. Illuminate offered one year of Kroll credit monitoring to eligible adults in the Orange Unified supplemental-notice population; offers and eligibility may have differed across populations. The evidence ledger retains 1 disputed claim with the original citations rather than silently resolving the conflict. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2][3][4][5]