Mathway Data Breach | The Odyssey Online
Start writing a post

Mathway Data Breach

A notorious group of threat actors release 25 million user records from Mathway

243
Mathway Data Breach

A data breach broker, known as ShinyHunters, offered to sell a database consisting of 25 million Mathway user records on a marketplace in the dark web. Mathway is a free math problem-solving app that can solve a user's math problems with a snap of a picture. It has over 10 million downloads on google play store and app store.


This breach was one of the latest compared to the many other breaches carried out by the same threat actor. They were also responsible for leaking sensitive data from Tokopedia, Wishbone, Zoosk, and many other companies.


It is recommended that users reset their passwords because according to Mathway, the passwords itself weren't acquired, but rather the cryptographically protected version of it were. Even though not much personal information has been acquired from this breach, it's still something to be cautious about because if a breached account contained an email address and a password, the hacker's first instinct would be to try logging into the user's email account with the same credentials because many people have the tendency to use the same password across many different sites.


According to the interview given by ShinyHunters to ZDNet, it is confirmed that the Mathway breach took place in January 2020. The hackers have accessed the company's backend and removed access to the database to avoid detection. At the start of May, the data from Mathway has been on sale on the darkweb for around $4,000 in Bitcoin and Monero. This type of data is valuable to other cybercrime gangs because it contains email addresses and hashed passwords. But it's unclear whether the hashed passwords can be reverted to their cleartext forms because the password hashing algorithm is unknown.


A big mistake that Mathway has made is not having proper access and privilege controls. In an IT environment, an organization can prevent a sophisticated cyberattack from affecting sensitive data by controlling who has privileges to access what.


Another mistake that Mathway made is using an outdated cryptographic hash known as MD5 to protect user's passwords. Millions of these password hashes can be hacked every second. The company should've used a more secure cryptographic hash to make the computing a lot slower. A salt should also be added on top of the cryptographic hash for extra security.


According to Scott Gordon, CISSP of Pulse Secure, the education sector is prone to many vulnerabilities during this period of time because they need adjust their operations to accommodate millions of students and teachers throughout the United States because of Covid-19. Gordon weighs in on the point he makes: "The EdTech digital marketplace is being targeted for cyberattacks and should consider more progressive security controls as institutions, parents and students seek additional online options to facilitate e-learning. Popular learning apps are often fertile ground for hackers - the ShinyHunters breach of Mathway is a prime example. As the breach exposed 25 million emails and passwords, there is the likelihood that some identity theft will go beyond consumer impact and actually expose organizations."


One major lesson that can be learned from this breach is that there is no reason to rely on credentials such as passwords when there are better ways to improve security.

Report this Content
This article has not been reviewed by Odyssey HQ and solely reflects the ideas and opinions of the creator.
Entertainment

Every Girl Needs To Listen To 'She Used To Be Mine' By Sara Bareilles

These powerful lyrics remind us how much good is inside each of us and that sometimes we are too blinded by our imperfections to see the other side of the coin, to see all of that good.

682355
Every Girl Needs To Listen To 'She Used To Be Mine' By Sara Bareilles

The song was sent to me late in the middle of the night. I was still awake enough to plug in my headphones and listen to it immediately. I always did this when my best friend sent me songs, never wasting a moment. She had sent a message with this one too, telling me it reminded her so much of both of us and what we have each been through in the past couple of months.

Keep Reading...Show less
Zodiac wheel with signs and symbols surrounding a central sun against a starry sky.

What's your sign? It's one of the first questions some of us are asked when approached by someone in a bar, at a party or even when having lunch with some of our friends. Astrology, for centuries, has been one of the largest phenomenons out there. There's a reason why many magazines and newspapers have a horoscope page, and there's also a reason why almost every bookstore or library has a section dedicated completely to astrology. Many of us could just be curious about why some of us act differently than others and whom we will get along with best, and others may just want to see if their sign does, in fact, match their personality.

Keep Reading...Show less
Entertainment

20 Song Lyrics To Put A Spring Into Your Instagram Captions

"On an island in the sun, We'll be playing and having fun"

580765
Person in front of neon musical instruments; glowing red and white lights.
Photo by Spencer Imbrock on Unsplash

Whenever I post a picture to Instagram, it takes me so long to come up with a caption. I want to be funny, clever, cute and direct all at the same time. It can be frustrating! So I just look for some online. I really like to find a song lyric that goes with my picture, I just feel like it gives the picture a certain vibe.

Here's a list of song lyrics that can go with any picture you want to post!

Keep Reading...Show less
Chalk drawing of scales weighing "good" and "bad" on a blackboard.
WP content

Being a good person does not depend on your religion or status in life, your race or skin color, political views or culture. It depends on how good you treat others.

We are all born to do something great. Whether that be to grow up and become a doctor and save the lives of thousands of people, run a marathon, win the Noble Peace Prize, or be the greatest mother or father for your own future children one day. Regardless, we are all born with a purpose. But in between birth and death lies a path that life paves for us; a path that we must fill with something that gives our lives meaning.

Keep Reading...Show less

Subscribe to Our Newsletter

Facebook Comments