Gale, a Cengage Company

Thanks for the email Gale, a Cengage Company!

This went out to all our patrons who registered with Gale Courses today. It’s neat how one of their immediate actions was to take customer support websites offline.

Dear Sir or Madam:

At Gale, we take seriously our commitment to protect the privacy and security of the data entrusted to us. We value our relationship with you, which is why we are writing to inform you about an incident that affects some of your information.

Gale recently learned of an incident that exposed your name and email address. This information was accessed via a publicly facing Gale website. Because there is no sensitive personal information provided at this website, no financial data or social security numbers were exposed.

Upon learning of this, we took immediate steps to contain the incident – including temporarily moving some Gale customer support websites offline. We also engaged Optiv, a leading cybersecurity solutions firm, to assist us in our review and remediation efforts. The investigation has concluded, and Optiv has determined that the affected server contained limited contact information; specifically, your name and email address.

A few important facts:

  • There is no indication that any of the information exposed in this incident has been used inappropriately.
  • There is no evidence that other contact information was impacted.
  • This incident does not impact Gale products. Gale products are hosted and secured separately. As such, any personal data associated with those products were never accessed.
  • You can continue to use our websites, including Gale Pages and statewide portals, as well as customer support hubs like support.gale.com.

We remain committed to safeguarding the privacy and security of the information entrusted to us, and we continue to implement additional measures to prevent future incidents. These measures include continuously updating our information security protocols and enhancing employee training in line with industry best practices.

We apologize that this happened and regret any concern it may cause. We understand you may have further questions and have included some Q&A below. For more information, please visit www.gale.com/incidentresponse. We also have set up a dedicated call center for you to ask questions at 1-833-281-4830 (US) and +1 512-777-3041 (international), available Monday through Friday, 6 am to 8 pm, Pacific Time and Saturday through Sunday, 8 am to 5 pm, Pacific Time, or you can email security@gale.com.

Sincerely,

Michael E. Hansen
CEO, Cengage

Q&A

  1. What happened?
    Gale recently learned of an incident that exposed your name and email address. This information was accessed via a publicly facing Gale website. Upon learning this, we took immediate steps to contain the incident – including temporarily moving some Gale websites offline. We also engaged Optiv, a leading cybersecurity solutions firm, to assist us in our review and mediation efforts. The investigation has concluded, and Optiv has determined that the affected server contained limited contact information; specifically, names and email addresses.
  2. Why was I notified?
    While there is no indication that any of the information exposed in this incident has been used inappropriately, we deeply value our relationships and are notifying out of an abundance of caution. We remain committed to safeguarding the privacy and security of the information entrusted to us, and we continue to implement additional measures to prevent future incidents.
  3. What of my information may have been affected?
    The data involved included limited contact information; specifically, names and email addresses. Because there is no sensitive personal information provided at this website, no financial data or social security numbers were exposed.

It is important to note that there is no indication that any of the information exposed in this incident has been used inappropriately, and there is no evidence that other information was impacted. This incident doesn’t impact Gale products and customers can continue to use our websites, including Gale Pages and statewide portals, as well as customer support hubs like support.gale.com.
4. Was any financial information affected?
No. This incident only affected contact names and email addresses.