The U.S. securities regulator said it had found that Pearson issued “misleading statements and omissions” about the breach, which led to the theft of millions of student login details.
Kristina Littman, chief of the SEC Enforcement Division’s Cyber Unit, said that “Pearson opted not to disclose this breach to investors until it was contacted by the media, and even then Pearson understated the nature and scope of the incident, and overstated the company’s data protections.”