Pearson to pay $1 mln to settle charges it misled investors, U.S. SEC says

WASHINGTON, Aug 16 (Reuters) – London-based Pearson PLC (PSON.L) will pay $1 million to settle charges it misled investors about a 2018 cyber intrusion involving the theft of millions of student records, the U.S. Securities and Exchange Commission (SEC) said on Monday.

The educational-publishing firm did not admit nor deny the regulator’s charges, the SEC said, but in 2019 the firm disclosed in its annual report that the data breach may have included birth dates and email addresses, when, in fact, it knew that such records were stolen.

Pearson also said at the time that it had “strict protections” in place, but failed to patch the critical vulnerability for six months after it was notified, the SEC found.

“Pearson opted not to disclose this breach to investors until it was contacted by the media, and even then Pearson understated the nature and scope of the incident, and overstated the company’s data protections,” said Kristina Littman, chief of the SEC enforcement division’s cyber unit.

“As public companies face the growing threat of cyber intrusions, they must provide accurate information to investors about material cyber incidents.”

Pearson spokesman Tom Steiner said the company’s data breach involved a web-based software tool that was retired in July 2019, and that the firm “continues to enhance its cyber security efforts to minimise the risk of cyberattacks in an ever-changing threat landscape.”

It has also agreed to cease and desist from committing violations of cyber-related disclosure provisions in addition to paying the civil penalty, the SEC said.

The top U.S. markets watchdog has brought a handful of other cybersecurity disclosure cases, including its nearly $500,000 fine in 2019 of real estate title insurance company First American and a $35 million settlement in 2018 to resolve allegations that Yahoo didn’t tell investors about a data breach.

It also warned companies in a 2018 report on corporations that were victims of cyber fraud that publicly-traded companies must adopt robust internal controls to detect cyber threats.Reporting by Tim Ahmann and Katanga Johnson Editing by Paul Simao

Our Standards: The Thomson Reuters Trust Principles.

Source: https://www.reuters.com/business/pearson-plc-pay-1-mln-settle-charges-it-misled-investors-us-sec-2021-08-16/

World Economic Magazine

Recent Posts

3D Printed Boats Prepare to Rewrite the Future of Marine Manufacturing

After years of material science breakthroughs, a team proved that a rugged, sea-ready composite could…

1 day ago

TAHO Raises 3.5 Million Seed Round to Redefine Compute Infrastructure for the AI Era

TAHO, a Venice-based compute startup founded by ex-Meta and Google engineers, raised $3.5 million in…

3 days ago

Squirrel AI Founder Haoyang Li Spotlights Global Talent Transformation

The 9th Future Investment Initiative in Riyadh spotlighted how AI is rapidly redefining global growth,…

4 days ago

Onward Robotics Names Brendon Bielat Chief Product Officer

Onward Robotics has appointed Brendon Bielat as Chief Product Officer, strengthening its leadership team as…

5 days ago

MOHAMMED BEN SULAYEM RE-ELECTED AS PRESIDENT OF THE FIA

Dubai, UAE, 12th December, 2025: The Fédération Internationale de l’Automobile (FIA), the global governing body for motor sport…

5 days ago

FIA, FORMULA 1 GROUP AND ALL 11 RACE TEAMS OFFICIALLY SIGN NINTH CONCORDE AGREEMENT

FIA President Mohammed Ben Sulayem says new agreement secures the FIA Formula One World Championship’s…

5 days ago