Mathway Data Breach | The Odyssey Online
Start writing a post

Mathway Data Breach

A notorious group of threat actors release 25 million user records from Mathway

209
Mathway Data Breach

A data breach broker, known as ShinyHunters, offered to sell a database consisting of 25 million Mathway user records on a marketplace in the dark web. Mathway is a free math problem-solving app that can solve a user's math problems with a snap of a picture. It has over 10 million downloads on google play store and app store.


This breach was one of the latest compared to the many other breaches carried out by the same threat actor. They were also responsible for leaking sensitive data from Tokopedia, Wishbone, Zoosk, and many other companies.


It is recommended that users reset their passwords because according to Mathway, the passwords itself weren't acquired, but rather the cryptographically protected version of it were. Even though not much personal information has been acquired from this breach, it's still something to be cautious about because if a breached account contained an email address and a password, the hacker's first instinct would be to try logging into the user's email account with the same credentials because many people have the tendency to use the same password across many different sites.


According to the interview given by ShinyHunters to ZDNet, it is confirmed that the Mathway breach took place in January 2020. The hackers have accessed the company's backend and removed access to the database to avoid detection. At the start of May, the data from Mathway has been on sale on the darkweb for around $4,000 in Bitcoin and Monero. This type of data is valuable to other cybercrime gangs because it contains email addresses and hashed passwords. But it's unclear whether the hashed passwords can be reverted to their cleartext forms because the password hashing algorithm is unknown.


A big mistake that Mathway has made is not having proper access and privilege controls. In an IT environment, an organization can prevent a sophisticated cyberattack from affecting sensitive data by controlling who has privileges to access what.


Another mistake that Mathway made is using an outdated cryptographic hash known as MD5 to protect user's passwords. Millions of these password hashes can be hacked every second. The company should've used a more secure cryptographic hash to make the computing a lot slower. A salt should also be added on top of the cryptographic hash for extra security.


According to Scott Gordon, CISSP of Pulse Secure, the education sector is prone to many vulnerabilities during this period of time because they need adjust their operations to accommodate millions of students and teachers throughout the United States because of Covid-19. Gordon weighs in on the point he makes: "The EdTech digital marketplace is being targeted for cyberattacks and should consider more progressive security controls as institutions, parents and students seek additional online options to facilitate e-learning. Popular learning apps are often fertile ground for hackers - the ShinyHunters breach of Mathway is a prime example. As the breach exposed 25 million emails and passwords, there is the likelihood that some identity theft will go beyond consumer impact and actually expose organizations."


One major lesson that can be learned from this breach is that there is no reason to rely on credentials such as passwords when there are better ways to improve security.

Report this Content
This article has not been reviewed by Odyssey HQ and solely reflects the ideas and opinions of the creator.
Featured

15 Mind-Bending Riddles

Hopefully they will make you laugh.

190037
 Ilistrated image of the planet and images of questions
StableDiffusion

I've been super busy lately with school work, studying, etc. Besides the fact that I do nothing but AP chemistry and AP economics, I constantly think of stupid questions that are almost impossible to answer. So, maybe you could answer them for me, and if not then we can both wonder what the answers to these 15 questions could be.

Keep Reading...Show less
Entertainment

Most Epic Aurora Borealis Photos: October 2024

As if May wasn't enough, a truly spectacular Northern Lights show lit up the sky on Oct. 10, 2024

14793
stunning aurora borealis display over a forest of trees and lake
StableDiffusion

From sea to shining sea, the United States was uniquely positioned for an incredible Aurora Borealis display on Thursday, Oct. 10, 2024, going into Friday, Oct. 11.

It was the second time this year after an historic geomagnetic storm in May 2024. Those Northern Lights were visible in Europe and North America, just like this latest rendition.

Keep Reading...Show less
 silhouette of a woman on the beach at sunrise
StableDiffusion

Content warning: This article contains descriptions of suicide/suicidal thoughts.

When you are feeling down, please know that there are many reasons to keep living.

Keep Reading...Show less
Relationships

Power of Love Letters

I don't think I say it enough...

457774
Illistrated image of a letter with 2 red hearts
StableDiffusion

To My Loving Boyfriend,

  • Thank you for all that you do for me
  • Thank you for working through disagreements with me
  • Thank you for always supporting me
  • I appreciate you more than words can express
  • You have helped me grow and become a better person
  • I can't wait to see where life takes us next
  • I promise to cherish every moment with you
  • Thank you for being my best friend and confidante
  • I love you and everything you do

To start off, here's something I don't say nearly enough: thank you. Thank you, thank you, thank you from the bottom of my heart. You do so much for me that I can't even put into words how much I appreciate everything you do - and have done - for me over the course of our relationship so far. While every couple has their fair share of tiffs and disagreements, thank you for getting through all of them with me and making us a better couple at the other end. With any argument, we don't just throw in the towel and say we're done, but we work towards a solution that puts us in a greater place each day. Thank you for always working with me and never giving up on us.

Keep Reading...Show less
Lifestyle

11 Signs You Grew Up In Hauppauge, NY

Because no one ever really leaves.

26586
Map of Hauppauge, New York
Google

Ah, yes, good old Hauppauge. We are that town in the dead center of Long Island that barely anyone knows how to pronounce unless they're from the town itself or live in a nearby area. Hauppauge is home to people of all kinds. We always have new families joining the community but honestly, the majority of the town is filled with people who never leave (high school alumni) and elders who have raised their kids here. Around the town, there are some just some landmarks and places that only the people of Hauppauge will ever understand the importance or even the annoyance of.

Keep Reading...Show less

Subscribe to Our Newsletter

Facebook Comments