Menu
Browse

Cyber Incident Victim: Wyzant

Date:

Apr 2019

Location:

United States of America

Summary

An online tutoring platform experienced a data breach after an attacker infiltrated its systems, potentially compromising users' names, email addresses, ZIP codes, and Facebook profile pictures for those who used social media login. The incident was detected following an anomaly in a database, though passwords, activity records, and financial information remained unaffected. The company addressed the vulnerability and initiated an investigation, though the exact number of impacted individuals—among its millions of registered users and tutors—remains unclear.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On April 27, 2019, an unauthorized actor infiltrated systems belonging to Wyzant, an online tutoring marketplace connecting students with instructors. The intrusion remained undetected until May 2, 2019, when company personnel identified an anomaly within a single database. This discovery triggered an investigation that confirmed unauthorized access to personally identifiable information (PII). Compromised data included user names, email addresses, and ZIP codes. Individuals who had authenticated through Facebook integration also had their social media profile pictures exposed. The platform explicitly stated that passwords, financial records, and user activity logs were not accessed or exfiltrated during the breach. Wyzant did not disclose the exact number of affected accounts but acknowledged its overall user base exceeded two million registered students and 80,000 tutors. The company did not specify whether both student and tutor accounts were compromised or if the breach disproportionately impacted one user group.

Cyber Incident Image

Wyzant contained the incident by patching the underlying vulnerability that enabled the attacker's access, though technical details of the exploit were not publicly released. Internal audits and forensic investigations commenced immediately following breach discovery to assess the full scope and attack methodology. No evidence suggested misuse of exposed data at the time of notification. Impacted individuals received direct email communications outlining the compromised data types while being advised to monitor for potential phishing attempts leveraging their exposed information. The company emphasized ongoing security enhancements but provided no specifics regarding additional protective measures implemented beyond the initial patch. Operational systems remained functional throughout the incident response period, with no reported service disruptions attributed to the breach or remediation efforts.

Sources
Sources available to members
1 source