Data breach
Mathway
- Records
- 25,695,755
- Breach date
- 13 January 2020Estimated
- Added
- 1 December 2024
What was exposed
3 types of data · 1 more reported
- Email addresses25,693,481
- Names9,927,344
- Facebook profiles4,340,106
- PasswordsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A database belonging to Mathway, the popular math-solving app and website, was breached in early 2020, exposing tens of millions of user accounts. Our investigation team estimates the dataset tied to this incident contains 25,695,755 records, including roughly 25.7 million email addresses. The breach drew wide attention in May 2020, when ZDNet reported that the data was being sold on a dark web marketplace and later leaked more broadly on Telegram channels. The hack was attributed to the attacker known as ShinyHunters, who told ZDNet in an interview that the intrusion took place in January 2020. Mathway, now part of education company Chegg, confirmed the incident and forced password resets across its user base.
January 2020: The attacker told ZDNet the Mathway hack took place this month; a database was accessed and copied from the company's backend.
May 15, 2020: Mathway, investigating after receiving a tip, confirmed its data had been improperly acquired, according to the company's security notice.
May 20, 2020: Mathway posted a security update saying it had retained a data security firm, introduced additional security measures, and was coordinating with law enforcement.
May 22, 2020: ZDNet published details of the breach, and Mathway began requiring password resets for all accounts. The company also filed a breach report with the California Attorney General that day.
May 24, 2020: Security Affairs reported that ShinyHunters was offering 25 million Mathway user records for sale on a dark web marketplace.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (about 25.7 million), Facebook account identifiers (about 4.3 million), and names (about 9.9 million).
Mathway's own security notice stated that the information involved included the email address used to log into Mathway and the hashed and salted password associated with each account. The company said the passwords themselves were not taken, only cryptographically protected versions, and that it had no reason to believe customer credit card or further personal information was affected.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because the dataset centers on email addresses and passwords, the primary risk is account compromise. If the hashed passwords can be cracked, attackers could try those passwords on other websites where users reused them. Even with hashed passwords, email addresses alone support phishing campaigns, since scammers can pose as Mathway or Chegg to trick users into revealing credentials.
The dataset also included Facebook identifiers and names, which can enrich targeted phishing or impersonation attempts. ZDNet noted that many affected accounts likely belong to children and students, given the app's audience. There is no evidence in the verified record that payment card data was taken.
What Is Mathway Doing in Response?
According to the company's security notice, Mathway retained a data security firm to investigate and fix vulnerabilities, monitored its systems for unauthorized access, introduced additional security measures, and coordinated with law enforcement. The company said it notified potentially impacted customers and required password resets for all accounts. Users logging in after May 22, 2020 were prompted to reset their passwords. Mathway stated that subscription payment information is stored in a separate system and that there was no evidence of access to it.
What Should You Do If You Were Affected?
Change your Mathway password if you have not done so since May 2020. Use a strong, unique password.
Change that password anywhere else you reused it. Password reuse is the fastest way a single breach spreads to other accounts.
Turn on two-factor authentication where the service offers it, including your email account and Facebook.
Be cautious with email claiming to come from Mathway or Chegg. Avoid clicking links in unexpected messages; go to the site directly instead.
Watch for suspicious login alerts on linked accounts, and consider reviewing connected apps on your Facebook account.
In the news
- ZDNet: 25 million user records leak online from popular math app Mathwayzdnet.com (opens in a new tab)
- Mathway security notice, May 20, 2020mathway.com (opens in a new tab)
- California Attorney General breach report filing for Mathway LLCoag.ca.gov (opens in a new tab)
- Security Affairs: 25 million Mathway user records available for sale on the dark websecurityaffairs.com (opens in a new tab)
- UNM Information Security & Privacy Office advisoriesispo.unm.edu (opens in a new tab)
