FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #38
FTC WARNS

The FTC finalized an order against an education technology company over data security failures that exposed the personal data of 10.1 million students.

HIGH CONFIDENCEPublished 2026-08-21
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

The Federal Trade Commission has given final approval to an order against Illuminate Education Inc. to settle allegations that its data security failures led to a major breach of student data. According to the FTC's complaint, a hacker accessed the personal data of 10.1 million students, including email and mailing addresses, dates of birth, student records and health-related information. The complaint further alleges the company was warned about numerous security vulnerabilities by a third-party vendor almost two years before the breach and failed to adequately address them, and that it did not notify schools about the breach in a timely manner as promised. Under the finalized order the company must delete unnecessary personal information, limit what it collects, follow a published retention schedule, run an information security program, and tell the FTC when it reports a breach to another government body. The harvested FTC release does not say that any of the exposed student data has been used to contact or defraud anyone, and it does not name the affected school districts or students. We have no harvested material showing scam messages built on this breach, so treat this as an exposure notice rather than a report of an active approach. If a message arrives that quotes a student's date of birth, address or school records to prove it is genuine, stop and contact the school district yourself on a number or address you already had, before replying or clicking anything. LIVEFRAUD ALERTS is independent and not affiliated with the FTC or with any company named above, which is named only because an official source named it; this alert was written solely from the public record cited here.
THE RULE
Detailed student records now outside the company's control give a caller or emailer the exact personal details that make a fake school or benefits approach sound real.

What we don’t know

The bench — who voted

3 INDEPENDENT AI MODELS REVIEWED THIS. ALL 3: MODERATE RISK.

The card names a count. Here are the seats behind it, with what each one said.

ANTHROPICclaude-opus-5 · MODERATE
The single evidence row supports only three facts: that the FTC finalized a modified order against Illuminate Education Inc., that the order requires the company to secure, limit and delete consumer data, and that the FTC alleged a hacker reached the personal data of 10.1 million students. The finding adds a large body of detail with no evidentiary support: the specific data categories (email and mailing addresses, dates of birth, student records, health-related information), the allegation that a third-party vendor warned the company of numerous vulnerabilities almost two years before the breach, and the allegation that the company failed to notify schools in a timely manner as promised. Each of these is presented as 'according to the FTC's complaint' but no complaint text is in the harvested record.
DISSENT, PRESERVEDThe headline CLAIM is fully carried by the evidence and should not be discarded because the body overreaches; the fix is to strip the unsourced complaint detail and order terms, not to pull the alert.
DISSENT, PRESERVEDThe alert's honest framing deserves to be noted on the record: it states plainly that no harvested material shows the data being used in any scam, refuses to name districts or students, and tells the reader to verify through a channel they already had. That is the right shape for an exposure notice and the safety advice is not contingent on the disputed details.
DISSENT, PRESERVEDOn risk: I grade this moderate rather than high because there is no evidence of any active approach, but children's dates of birth and school records are unusually durable identity-fraud material with a long tail, so it should not be graded low either.
GROQopenai/gpt-oss-120b · MODERATE
Finding adds details (specific data fields, prior vendor warning, failure to notify schools, exact order requirements) not present in the sole evidence row, which only mentions a finalized order, breach of 10.1 million students, and a requirement to secure, limit and delete data.
OPENROUTERopenrouter/free · MODERATE
Raised no objection; read the evidence as holds.

Reviewed by 3 independent models: 1 found it carried by the evidence, 2 did not.

▼ Protocol & challenge record
Objection (medium): Top-line claim states as fact what the source states as allegation. The row says the FTC's complaint 'alleged' that security failures 'led to a major data breach, which allowed a hacker to access personal data of 10.1 million students.' The claim line asserts flatly that data security failures 'exposed the personal data of 10.1 million students.' A settled/finalized consent order is not an adjudicated finding of fact and, per standard FTC practice, carries no admission. The claim needs an 'alleged' hedge; the finding body hedges correctly, so the mismatch is between the claim and its own finding.
Resolved: Rewrite claim to: 'The FTC finalized an order against an education technology company over alleged data security failures that the agency says exposed the personal data of 10.1 million students.' Add to the finding that the settlement is not an admission of the allegations.
Objection (medium): The risk_line is not sourced and imports facts the release does not contain: 'Detailed student records now outside the company's control give a caller or emailer the exact personal details that make a fake school or benefits approach sound real.' Nothing in the harvested row says the data was exfiltrated, retained, sold, published, or is 'now' in anyone's hands. 'Access' by a hacker is what is alleged. The word 'now' also asserts present-tense continuing exposure, which the unknowns list explicitly concedes is unknown ('whether the access has ended'). This is the single largest source-to-claim stretch in the artifact and it sits in the field most likely to be read as the operative warning.
Resolved: Replace risk_line with a version that does not assert present possession or exfiltration, e.g. 'The FTC alleges a hacker reached student email and mailing addresses, dates of birth, records and health information — the kind of detail that makes a fake school or benefits approach sound convincing. The release does not say the data has been used.'
Objection (medium): Date/recency framing problem. The only dated facts in the row are the June 2026 final order and the December 2025 initial action. The breach itself is undated in the harvested material, and the complaint's own timeline ('almost two years before the breach' vendor warning) implies an incident well predating the release. The alert is packaged with a live-threat audience callout and 'if a message arrives' advice, which implies proximate exposure. What actually happened this week is an administrative finalization, not a new exposure event. The artifact should say plainly that the news is the order, and that the breach date is not in the harvested record.
Not resolved — preserved on the record.
Objection (high): directive_options are corrupted by filename-token extraction and must not be surfaced. 'Send this to any illuminatefinalorder you know' and 'Forward this to the illuminatefinalorders in your life' are derived from the PDF slugs 'illuminatefinalorder'/'illuminatefinalcomplaint' in the source HTML, not from any entity in the text. 'Send this to any commenter you know' is derived from the three public commenters on the rulemaking docket — an absurd targeting group. If any of these were selected, the output would be incoherent and would badly damage credibility. Even unselected, they indicate the entity extractor is reading URL path segments as person-type nouns, which is a defect that will recur on any FTC row.
Resolved: Suppress all four directive_options and blacklist tokens sourced from URL path segments and PDF filenames from the entity extractor. share_directive stays null, which was the right call; the options list should not have been generated at all.
Objection (medium): audience_callout 'ATTENTION: STUDENTS WHOSE DATA WAS BREACHED' asserts as fact the allegation flagged in OBJ-1, and is unusable as a self-selection cue because the release explicitly does not name districts or individuals — the artifact says so itself in its own limitation sentence. No reader can determine whether they are in the callout group. It also addresses students when the affected population is largely K-12 minors whose guardians would be the actual readers and the ones who would receive a pretext call.
Not resolved — preserved on the record.
Objection (low): 'Education technology company' in the claim is not stated in the harvested row's prose. The row says 'Wisconsin-based Illuminate' and characterizes it only as maintaining student data; the 'education technology provider' descriptor appears solely in the anchor text/URL of a linked December 2025 release. This is almost certainly true, but it is inference from a hyperlink, not from the harvested body, and should be tightened to what the row says.
Resolved: Change to 'a company that provides software to schools' or attribute the descriptor: 'described by the FTC in a related release as an education technology provider.'
Objection (low): Material order term omitted: the finalized order also prohibits Illuminate from misrepresenting its data security and privacy practices and how quickly it will notify districts and students about breaches. That is the conduct prohibition most directly relevant to a reader deciding whether future notices can be trusted, and it is dropped from the summary of order obligations.
Resolved: Add the misrepresentation prohibition to the order-terms sentence, including the specific ban on misrepresenting notification speed.
Objection (low): watch_icons includes 'link', which signals phishing-link risk. There is no harvested evidence of any message, link, or lure connected to this breach; the artifact's own limitation says so. 'link' should come out or the icon set should be justified as generic-advice illustration rather than observed-tactic signalling.
Resolved: Drop 'link' from watch_icons.
Objection (low): confidence 'high' is defensible for the enforcement facts but the confidence_reasons do not acknowledge that the artifact's headline risk framing (risk_line, callout, advice) rests on zero evidence. Confidence should be scoped in the reasons to the order and complaint allegations, with an explicit note that the fraud-risk framing is inference.
Resolved: Add a confidence_reason: 'The fraud-risk framing, callout and advice are inference from the data categories, not from harvested evidence of any approach.'
Preserved dissent
ON THE RECORDI do not accept 'high' confidence on this artifact as a whole. The enforcement facts are single-source but that source is primary and official, so those are solid. What is not solid is everything the reader will actually act on: the risk_line asserts that detailed student records are 'now outside the company's control', and no harvested word supports 'now' or 'outside'. The artifact's own unknowns list concedes it does not know whether the access has ended. A confidence rating that covers the whole object while the operative warning rests on inference is a rating that will mislead a downstream reviewer.
ON THE RECORDThe directive_options in this artifact are a serious quality failure, not a cosmetic one. 'Send this to any illuminatefinalorder you know' is a PDF filename being treated as a category of person. That the correct option (null) was chosen is luck of the draw from a menu of nonsense, and I want it recorded that the generator was reading URL slugs as entities on an official FTC row — the most common source type in this feed.
ON THE RECORDMy honest read of the news value: the breach is old, the enforcement action was announced in December 2025, and the only new fact on 5 June 2026 is that the Commission voted 2-0 to finalize after three public comments. Dressing an administrative finalization in an 'ATTENTION: STUDENTS WHOSE DATA WAS BREACHED' banner with 'if a message arrives' advice overstates urgency. I would run this as a record-of-action item, not as an alert.

The sources

Official sourceFTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students’ Personal Data2026-06-05
The FTC finalized a modified order requiring Illuminate Education Inc. to secure, limit and delete consumer data after alleging its failures allowed a hacker to reach the personal data of 10.1 million students.
Authority: official. Retrieved 2026-08-21.
Limitation: The release describes the enforcement action and the alleged breach only; it reports no fraud, no contact with affected students, and does not identify the districts or individuals involved.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/M8KnrgU

Published under standing founder pass (A9) — every claim source-mapped by the machine.

▼ What the machine checked
  • ✓ Not a community submission.
  • ✗ Draws on an FTC enforcement release, which names a defendant: "FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Fai".
  • ✓ All 4 material sentence(s) map to FTC.
  • ✗ anthropic returned "overstated"; groq returned "overstated" — published on the receipt, not blocking (A9 amendment).
  • ✓ No audience band is set.

No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-08-21.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.