The WizTango Breach Put 50,019 Names, Emails, and MD5 Password Hashes Online in 2020
HEROIC analysts identified a database breach at WizTango, a U.S.-based online educational platform, that occured in 2020. The breach exposed 50,019 records containing email addresses, phone numbers, full names, IP addresses, salts, and password hashes using MD5 with salting. The combination of personally identifiable information and hashed credentials creates a broad attack surface for anyone who recieved access to this dataset.
What Attackers Can Do With MD5-Hashed Passwords, Names, and IP Addresses
MD5 is a weak hashing algorithm and is partcularly vulnerable to cracking using precomputed rainbow tables and modern GPU-accelerated tools. Even with salting, MD5 hashes can often be reversed within hours using commodity hardware. Once an attacker recovers a plaintext password, they can test it against other platforms where the same email was used. The inclusion of full names, phone numbers, and IP addresses provides additional targeting data for phishing, identity fraud, and account takeover.
What Was Exposed in the WizTango Breach
- Email Address
- Phone Number
- Password Hash
- First Name
- Last Name
- IP Address
- Salt
Why an Education Platform Breach Puts Users at Elevated Risk
Educational platforms often hold accounts belonging to students and professionals who registered with personal or institutional email addresses. Those email addresses are frequently reused across banking, healthcare, and workplace systems. The WizTango breach is seperate from many credential leaks because it combines authentication data with real names and phone numbers, enabling attackers to launch personalized social engineering attacks that go beyond automated credential stuffing.
How Database Breaches Work
A database breach occurs when an unauthorized party extracts records from a backend database, typically by exploiting application vulnerabilities, unprotected storage endpoints, or compromised server credentials. The stolen data is then circulated on dark web forums or messaging channels and used in follow-on attacks against the individuals whose information was exposed.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion records, including data from the WizTango breach. Enter your email address to find out if your name, phone number, or hashed password was part of this or any other known breach dataset.
Breach Breakdown
50,019 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds