Mathway Data Breach
Start writing a post

Mathway Data Breach

A notorious group of threat actors release 25 million user records from Mathway

184
Mathway Data Breach

A data breach broker, known as ShinyHunters, offered to sell a database consisting of 25 million Mathway user records on a marketplace in the dark web. Mathway is a free math problem-solving app that can solve a user's math problems with a snap of a picture. It has over 10 million downloads on google play store and app store.


This breach was one of the latest compared to the many other breaches carried out by the same threat actor. They were also responsible for leaking sensitive data from Tokopedia, Wishbone, Zoosk, and many other companies.


It is recommended that users reset their passwords because according to Mathway, the passwords itself weren't acquired, but rather the cryptographically protected version of it were. Even though not much personal information has been acquired from this breach, it's still something to be cautious about because if a breached account contained an email address and a password, the hacker's first instinct would be to try logging into the user's email account with the same credentials because many people have the tendency to use the same password across many different sites.


According to the interview given by ShinyHunters to ZDNet, it is confirmed that the Mathway breach took place in January 2020. The hackers have accessed the company's backend and removed access to the database to avoid detection. At the start of May, the data from Mathway has been on sale on the darkweb for around $4,000 in Bitcoin and Monero. This type of data is valuable to other cybercrime gangs because it contains email addresses and hashed passwords. But it's unclear whether the hashed passwords can be reverted to their cleartext forms because the password hashing algorithm is unknown.


A big mistake that Mathway has made is not having proper access and privilege controls. In an IT environment, an organization can prevent a sophisticated cyberattack from affecting sensitive data by controlling who has privileges to access what.


Another mistake that Mathway made is using an outdated cryptographic hash known as MD5 to protect user's passwords. Millions of these password hashes can be hacked every second. The company should've used a more secure cryptographic hash to make the computing a lot slower. A salt should also be added on top of the cryptographic hash for extra security.


According to Scott Gordon, CISSP of Pulse Secure, the education sector is prone to many vulnerabilities during this period of time because they need adjust their operations to accommodate millions of students and teachers throughout the United States because of Covid-19. Gordon weighs in on the point he makes: "The EdTech digital marketplace is being targeted for cyberattacks and should consider more progressive security controls as institutions, parents and students seek additional online options to facilitate e-learning. Popular learning apps are often fertile ground for hackers - the ShinyHunters breach of Mathway is a prime example. As the breach exposed 25 million emails and passwords, there is the likelihood that some identity theft will go beyond consumer impact and actually expose organizations."


One major lesson that can be learned from this breach is that there is no reason to rely on credentials such as passwords when there are better ways to improve security.

Report this Content
This article has not been reviewed by Odyssey HQ and solely reflects the ideas and opinions of the creator.
​a woman sitting at a table having a coffee
nappy.co

I can't say "thank you" enough to express how grateful I am for you coming into my life. You have made such a huge impact on my life. I would not be the person I am today without you and I know that you will keep inspiring me to become an even better version of myself.

Keep Reading...Show less
Student Life

Waitlisted for a College Class? Here's What to Do!

Dealing with the inevitable realities of college life.

72108
college students waiting in a long line in the hallway
StableDiffusion

Course registration at college can be a big hassle and is almost never talked about. Classes you want to take fill up before you get a chance to register. You might change your mind about a class you want to take and must struggle to find another class to fit in the same time period. You also have to make sure no classes clash by time. Like I said, it's a big hassle.

This semester, I was waitlisted for two classes. Most people in this situation, especially first years, freak out because they don't know what to do. Here is what you should do when this happens.

Keep Reading...Show less
a man and a woman sitting on the beach in front of the sunset

Whether you met your new love interest online, through mutual friends, or another way entirely, you'll definitely want to know what you're getting into. I mean, really, what's the point in entering a relationship with someone if you don't know whether or not you're compatible on a very basic level?

Consider these 21 questions to ask in the talking stage when getting to know that new guy or girl you just started talking to:

Keep Reading...Show less
Lifestyle

Challah vs. Easter Bread: A Delicious Dilemma

Is there really such a difference in Challah bread or Easter Bread?

46038
loaves of challah and easter bread stacked up aside each other, an abundance of food in baskets
StableDiffusion

Ever since I could remember, it was a treat to receive Easter Bread made by my grandmother. We would only have it once a year and the wait was excruciating. Now that my grandmother has gotten older, she has stopped baking a lot of her recipes that require a lot of hand usage--her traditional Italian baking means no machines. So for the past few years, I have missed enjoying my Easter Bread.

Keep Reading...Show less
Adulting

Unlocking Lake People's Secrets: 15 Must-Knows!

There's no other place you'd rather be in the summer.

976957
Group of joyful friends sitting in a boat
Haley Harvey

The people that spend their summers at the lake are a unique group of people.

Whether you grew up going to the lake, have only recently started going, or have only been once or twice, you know it takes a certain kind of person to be a lake person. To the long-time lake people, the lake holds a special place in your heart, no matter how dirty the water may look.

Keep Reading...Show less

Subscribe to Our Newsletter

Facebook Comments