Supply chain ⛓ Supply Chain

GW community members Third-Party Breach (October 2019)

📅 2019-10-01 🏢 Chegg
Primary Source ↗

Incident Details

Officials admit to Chegg data breach affecting thousands of GW users’ account passwords. Officials notified students last week of a data leak revealing about 5,000 GW community members’ usernames and passwords to accounts with Chegg’s services. A popular educational technology company leaked thousands of GW community members’ usernames, passwords and addresses last year. Officials said Chegg – a company that offers students homework help and textbook rentals – admitted falling victim to a data breach in April 2018 that revealed the usernames and passwords of 5,000 members of the GW community and 40 million users globally. While the incident did not involve a breach of any University systems, officials said Division of Information Technology employees are helping affected students to make sure their information is secure. Third-party company: Chegg.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Chegg
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2019-10-01 Breach occurred
  2. 2019-10-01 Publicly disclosed