Cyber Incident Victim: Wyzant
Date:
Apr 2019
Location:
United States of America
Summary
An online tutoring platform experienced a data breach after an attacker infiltrated its systems, potentially compromising users' names, email addresses, ZIP codes, and Facebook profile pictures for those who used social media login. The incident was detected following an anomaly in a database, though passwords, activity records, and financial information remained unaffected. The company addressed the vulnerability and initiated an investigation, though the exact number of impacted individuals—among its millions of registered users and tutors—remains unclear.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On April 27, 2019, an unauthorized actor infiltrated systems belonging to Wyzant, an online tutoring marketplace connecting students with instructors. The intrusion remained undetected until May 2, 2019, when company personnel identified an anomaly within a single database. This discovery triggered an investigation that confirmed unauthorized access to personally identifiable information (PII). Compromised data included user names, email addresses, and ZIP codes. Individuals who had authenticated through Facebook integration also had their social media profile pictures exposed. The platform explicitly stated that passwords, financial records, and user activity logs were not accessed or exfiltrated during the breach. Wyzant did not disclose the exact number of affected accounts but acknowledged its overall user base exceeded two million registered students and 80,000 tutors. The company did not specify whether both student and tutor accounts were compromised or if the breach disproportionately impacted one user group.

Wyzant contained the incident by patching the underlying vulnerability that enabled the attacker's access, though technical details of the exploit were not publicly released. Internal audits and forensic investigations commenced immediately following breach discovery to assess the full scope and attack methodology. No evidence suggested misuse of exposed data at the time of notification. Impacted individuals received direct email communications outlining the compromised data types while being advised to monitor for potential phishing attempts leveraging their exposed information. The company emphasized ongoing security enhancements but provided no specifics regarding additional protective measures implemented beyond the initial patch. Operational systems remained functional throughout the incident response period, with no reported service disruptions attributed to the breach or remediation efforts.
