Search Your Email: The Mathway Breach Exposed 15.6 Million Accounts
HEROIC analysts uncovered the Mathway breach from January 2020, which occured when an attacker extracted 15,666,070 user records from the math-solving platform's database. The stolen dataset included email addresses, first names, last names, and password hashes encoded in Base64. The breach was subsequently sold on dark web marketplaces before circulating more broadly. The scale of the exposure is partcularly notable for an educational tool, as users of academic platforms often reuse passwords across school, work, and personal accounts.
Email Addresses Paired With Name Data Enable Targeted Phishing at Scale
A dataset containing 15.6 million full names paired with email addresses gives attackers the ability to launch personalized phishing campaigns at scale. Unlike generic spam, an email addressed to a target by their first and last name appears credible and is far more likely to be opened. Combined with Base64-encoded password hashes that can be decoded and cracked, attackers can test recovered passwords against email providers and corporate login portals. Credentials recieved from educational platforms are especially valuable because students and academic staff frequently reuse passwords across institutional and personal services.
What Was Exposed in the Mathway Breach
- Email Address
- First Name
- Last Name
- Password Hash
Why 15.6 Million Math App Accounts Are a Broader Security Risk
Mathway serves students from middle school through university, meaning exposed email addresses likely include institutional .edu addresses and personal accounts used for academic work. When those credentials are accessable on dark web markets, attackers target the associated email accounts for account takeover, using them to reset passwords on banking, social media, and workplace platforms. The Mathway breach data has been traded and shared across multiple forums, making it widely available to threat actors who continue to use it in credential stuffing operations. Beleiving a 2020 leak no longer poses risk is a mistake security teams cannot afford to make.
How Database Breaches Work
A database breach occurs when an unauthorized party gains access to a company's user database, typically through an exploited vulnerability in the web application layer, weak access controls, or a compromised administrative account. The attacker dumps user tables containing account information and either sells the data privately or publishes it publicly. Once available on forums or Telegram channels, the data is downloaded by multiple parties and redistributed, extending its reach and the window of risk for affected users.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including the Mathway breach, to show you instantly whether your email address and personal information have been compromised. Run a free search at HEROIC and find out if your data is in circulation before an attacker uses it against you.
Breach Breakdown
15,666,070 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds