Mathway Data Breach | The Odyssey Online
Start writing a post

Mathway Data Breach

A notorious group of threat actors release 25 million user records from Mathway

217
Mathway Data Breach

A data breach broker, known as ShinyHunters, offered to sell a database consisting of 25 million Mathway user records on a marketplace in the dark web. Mathway is a free math problem-solving app that can solve a user's math problems with a snap of a picture. It has over 10 million downloads on google play store and app store.


This breach was one of the latest compared to the many other breaches carried out by the same threat actor. They were also responsible for leaking sensitive data from Tokopedia, Wishbone, Zoosk, and many other companies.


It is recommended that users reset their passwords because according to Mathway, the passwords itself weren't acquired, but rather the cryptographically protected version of it were. Even though not much personal information has been acquired from this breach, it's still something to be cautious about because if a breached account contained an email address and a password, the hacker's first instinct would be to try logging into the user's email account with the same credentials because many people have the tendency to use the same password across many different sites.


According to the interview given by ShinyHunters to ZDNet, it is confirmed that the Mathway breach took place in January 2020. The hackers have accessed the company's backend and removed access to the database to avoid detection. At the start of May, the data from Mathway has been on sale on the darkweb for around $4,000 in Bitcoin and Monero. This type of data is valuable to other cybercrime gangs because it contains email addresses and hashed passwords. But it's unclear whether the hashed passwords can be reverted to their cleartext forms because the password hashing algorithm is unknown.


A big mistake that Mathway has made is not having proper access and privilege controls. In an IT environment, an organization can prevent a sophisticated cyberattack from affecting sensitive data by controlling who has privileges to access what.


Another mistake that Mathway made is using an outdated cryptographic hash known as MD5 to protect user's passwords. Millions of these password hashes can be hacked every second. The company should've used a more secure cryptographic hash to make the computing a lot slower. A salt should also be added on top of the cryptographic hash for extra security.


According to Scott Gordon, CISSP of Pulse Secure, the education sector is prone to many vulnerabilities during this period of time because they need adjust their operations to accommodate millions of students and teachers throughout the United States because of Covid-19. Gordon weighs in on the point he makes: "The EdTech digital marketplace is being targeted for cyberattacks and should consider more progressive security controls as institutions, parents and students seek additional online options to facilitate e-learning. Popular learning apps are often fertile ground for hackers - the ShinyHunters breach of Mathway is a prime example. As the breach exposed 25 million emails and passwords, there is the likelihood that some identity theft will go beyond consumer impact and actually expose organizations."


One major lesson that can be learned from this breach is that there is no reason to rely on credentials such as passwords when there are better ways to improve security.

Report this Content
This article has not been reviewed by Odyssey HQ and solely reflects the ideas and opinions of the creator.
gossip girl

On the Upper East Side, Blair Waldorf is an icon. She's what every girl aspires to be. She's beautiful, confident, and can handle any obstacle that life throws at her. Sure, she may just be a television character. But for me, she's a role model and theres a lot that can be learned from Queen B.

Keep Reading...Show less
Lifestyle

The Perks of Being a Girl

“I just want you to know that you’re very special… and the only reason I’m telling you is that I don’t know if anyone else ever has.”

738
girl

As frustrating and annoying as it can be, being a girl is really awesome. We are beautiful inside and out. Not a lot of people may see that, but girls have a ton of amazing qualities.

We have unique flirting skills.

Us girls have a significant way to flirt with other people. Even when we say the most random or awkward things, we have a way of making everything sound cute and planned. It’s just a gift; we’re good like that.

Keep Reading...Show less
gossip girl

Us college students know all about the struggle of spending the day in the library. Whether you are writing a ten-page paper, studying for a biology exam, or struggling through math homework, you somehow find the strength to get to the library to get it all done. Let's just say you have a lot of different thoughts that run through your head during the many hours you spend in the lovely library.

Keep Reading...Show less
female tv characters
We Heart It

Over the past decade, television has undergone a very crucial transition: the incorporation of female lead characters. Since it's a known fact that girls actually do run the world (Beyonce said so herself), it's time for the leading ladies of the small screen to get some credit. Without these characters, women would still be sitting in the background of our favorite shows. These women are not only trailblazers for female empowerment, but role models for women worldwide. With that, here are 15 of the smartest, sassiest ladies gracing our screens that remind us that women do, indeed, rule:

Keep Reading...Show less
New Now Next
New Now Next

If you are like me, you have an interesting personality. Basically, you love to be sassy and snarky, gossip, and act like a total bitch (not really), but deep down, you are actually a very genuinely nice person. The idea of actually hurting someone truly makes you feel bad, and you probably have never actually hurt someone’s feelings because your kindness always shines through, even if you do not want it to. Not sure exactly what I would call this type of personality, but if you identify with it, here are some feelings you can undoubtedly relate to.

Keep Reading...Show less

Subscribe to Our Newsletter

Facebook Comments