2018–2019 Pearson — AIMSweb 1.0 intrusion; millions of student rows & ~13k admin accounts (SEC enforcement)
Data compromised
Student assessment roster data and school administrator authentication material per SEC administrative order
Technical writeup
Pearson plc disclosed unauthorized access to legacy AIMSweb 1.0 assessment infrastructure following November 2018 activity, with patches delayed until March 2019 discovery according to the SEC’s 2021 settled order. Regulators alleged exfiltration affecting millions of data rows on students (e.g., names/DOB-class fields) plus ~13,000 institutional administrative user credentials, and faulted misleading investor messaging characterizing breach risk as hypothetical. This directory row uses the `pearson-education-india` slug present in the company catalog while the underlying operator is the global Pearson legal entity.
Root cause
Unpatched AIMSweb server exposure exploited by external intruder until remediation window (per SEC findings)