26 May 2020

25 million Mathway user records leak online


25 million Mathway user records leak online

A data brocker going by the name of ShinyHunters, is selling on the dark web marketplace a database that allegedly contains 25 million user records for Mathway, a popular free calculator app that provides users with the tools they need to understand and solve their math problems. The Mathway app has over 10 million installs on Android Play Store and the Apple Store.

Since the start of this month, ShinyHunters has been offering access to databases containing millions user records obtained from hacks of various companies, including Tokopedia, Wishbone, and the Microsoft’s GitHub account.

ShinyHunters told ZDNet that the Mathway hack took place in January 2020. The hacker has not disclosed the details of the breach, only saying that “they accessed the company's backend, dumped the database, and then removed access to avoid getting detected.”

The Mathway data, which included user emails and hashed passwords, was being sold for the equivalent of $4,000 in Bitcoin or Monero. Later, according to ZDNet, the copy of the Mathway database appeared on Telegram channels dedicated to "data brokers," a category of the cyber criminals that specialize in buying and reselling hacked data.

Mathway said in a statement that it is aware of reports of a potential data compromise and that it is investigating the issue.

Back to the list

Latest Posts

Cyber Security Week in Review: April 26, 2024

Cyber Security Week in Review: April 26, 2024

In brief: Cisco and CrushFTP patch zero-days, researchers sinkhole C&C server used by PlugX malware, and more.
26 April 2024
US charges Samourai cryptomixer founders with laundering $100 million

US charges Samourai cryptomixer founders with laundering $100 million

The cryptocurrency mixer facilitated over $2 billion in illegal transactions.
25 April 2024
ArcaneDoor state-sponsored malware campaign strikes Cisco networking gear

ArcaneDoor state-sponsored malware campaign strikes Cisco networking gear

The attackers exploited two zero-day vulnerabilities in Cisco networking equipment.
25 April 2024