[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f21e9bydga7e4p":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda4882513f","Chegg","Chegg Data Breach","chegg","chegg.com","2018-04-28T00:00:00.000Z","2019-08-16T07:24:58.000Z","2024-04-27T05:34:09.000Z","2026-07-18T23:47:21.814Z","Verified breach record","https:\u002F\u002Fwww.ftc.gov\u002Fnews-events\u002Fnews\u002Fpress-releases\u002F2022\u002F10\u002Fftc-brings-action-against-ed-tech-provider-chegg-careless-security-exposed-personal-data-millions",[16,18,19],"https:\u002F\u002Ftechcrunch.com\u002F2018\u002F09\u002F26\u002Fchegg-resets-40-million-user-passwords-after-data-breach\u002F","https:\u002F\u002Feliterate.us\u002Fchegg-data-breach-affecting-40-million-users\u002F",39721127,"known",null,"unknown","Critical",[26,27,28,29,30,31],"Email addresses","Names","Passwords","Phone numbers","Physical addresses","Usernames","\u003Cp>The Chegg data breach is related to unauthorized access to user data in the Chegg ecosystem, known for educational technology and textbook rental services, in April 2018. Verified notifications indicate that the incident could affect approximately 40 million active and former users, with the verified account set containing 39,721,127 email-based records. The leaked data mainly consists of names, email addresses, usernames, physical addresses, phone numbers, and password hashes. The fact that passwords were stored unsalted with the weak MD5 method increases the risk of account takeover for individuals who use the same password across different services.Due to Chegg's student-focused use, the incident is not limited to just a password change; when the educational account, personal contact information, and delivery address are evaluated together, a strong profile can be formed for targeted phishing, fake scholarship notifications, payment traps, and account recovery attempts.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The primary types of data confirmed in the Chegg leak are email addresses, names, usernames, passwords, phone numbers, and physical addresses. While an email address alone is a valuable indicator for phishing and account testing attacks, the username and name information personalizes this risk. In accounts with a physical address or phone number, attackers can prepare more convincing notifications, fake messages pretending to be delivery excuses, or calls impersonating a support center.\u003C\u002Fp>\n\u003Cp>The most critical element is password hashes. Due to weak and unsalted MD5 usage, the likelihood of cracking passwords is especially high for short, dictionary-based, or reused passwords. If a student or alumnus used the same password for their email account, school portal, file storage service, or payment account, the risk extends beyond the Chegg account. Therefore, the Chegg data breach should be seen not just as an old educational account incident, but as a broad identity security risk that can affect password reuse and account recovery questions.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The incident date has been confirmed as the end of April 2018. The impact reported by Chegg is at the level of approximately 40 million active and former users; in the verified query set, there are 39,721,127 accounts. This difference may be due to different reporting thresholds, cleaned duplicate rows, the scope of verifiable accounts, and the portion of the leaked set that was subsequently verified. The number shown on this page represents the verified record matched in users' account security queries.\u003C\u002Fp>\n\u003Cp>The main accepted scope for data fields includes name, email, username, password hash, physical address, and phone number. In additional official reviews, sensitive fields such as date of birth, parental income range, religious denomination, ethnic heritage, sexual orientation, and disability have been mentioned for certain user groups during the scholarship application process. However, the main data classes listed on this page are limited to the fields regularly monitored in the verified account set. This ensures that the user is not shown excessive or unconfirmed fields.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Students with Chegg accounts, alumni, teachers, users receiving course support, and people using the same email address for school or work accounts are the primary risk group. Due to Chegg's usage related to textbook rental, study assistance, writing, and citation services, a leak creates a favorable data ground for fake messages, especially during academic periods, scholarship applications, account renewal periods, and student discounts.\u003C\u002Fp>\n\u003Cp>Users who reuse passwords are also at high risk. If unsalted MD5 hashes are cracked, attackers may try the same email and password combination on different sites. For individuals with phone numbers or address information, fraud messages may appear more realistic. For those who registered with Chegg using a family email address, school account, or work account, the impact chain is broader; because it is possible to attempt access to other personal accounts, cloud files, or corporate services through the educational account.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Passwords must be immediately changed on all accounts where the same or similar password as Chegg is used. The new password should be unique for each service, generated with a password manager, and not used on any other account before. The email account, school portal, file storage service, social media account, and payment account should be checked first, as attackers usually target the email account first, and then the recovery flows of other accounts.\u003C\u002Fp>\n\u003Cp>Multi-factor authentication should be enabled, and account recovery email addresses and phone numbers should be reviewed. Before clicking on links in messages concerning Chegg, course support, scholarship opportunities, invoice refunds, or account verification, the domain name should be checked. Users whose address and phone information has been leaked should exercise extra caution against calls and messages claiming to be from shipping, student discounts, financial aid, or support centers. Suspicious sessions, password reset emails, and unknown device notifications should be closed quickly, and active sessions should be terminated through account security pages.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>The Chegg data breach shows that even old educational accounts can be used in account takeover attempts years later. Users should develop lasting habits such as regularly checking passwords, using a password manager, enabling multi-factor authentication, and using email aliases. Using separate email addresses for education, shopping, social media, and financial accounts reduces the likelihood of a single leak spreading to other accounts.\u003C\u002Fp>\n\u003Cp>In corporate and school accounts, password policies that prevent using the same password as student services, leaked password checks, and risky session alerts are important. Security teams should review email addresses associated with Chegg for password reuse risks and may request additional verification for high-risk users. On the user side, deleting old accounts, reducing unnecessary profile information, and keeping security notifications on provide long-term protection.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If the Chegg result appears in the account security query, it means that the relevant email address is included in the verified set of accounts associated with the 2018 Chegg data breach. This result does not mean that your current Chegg account is still compromised today; however, passwords, email addresses, and profile information used in the past can be used in attempts on other accounts. Therefore, changing the password and enabling multi-factor authentication wherever the same password is used should be the primary action.\u003C\u002Fp>\n\u003Cp>Even if the Chegg account is no longer in use, email security, recovery settings, and password history should be checked. The risk is higher if an educational account, work account, or personal email has been affected by the same password pattern. Users who may have a physical address or phone number in the leak should be more careful against fake support messages containing personal information. The most correct approach is, instead of seeing the Chegg result as an old notification and ignoring it, to stop password reuse, review session history, and strengthen account recovery channels.\u003C\u002Fp>","","Chegg Data Breach (39.7 Million Reported Records)","Chegg Data Breach. 39.7 Million reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective steps.","\u002Fuploads\u002Flogo\u002Fchegg_com.webp",false,{"name":7,"sector":39,"country":40,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":22},"Education technology platform","United States"]