Facebook-funded Unacademy data hacked, claims cybersecurity firm

Image
Press Trust of India New Delhi
Last Updated : May 07 2020 | 9:21 PM IST

Facebook-funded education technology firm Unacademy's data comprising over 20 million accounts has been hacked by cybercriminals and put up for sale in the dark web, according to cybersecurity firm Cyble.

The hackers have claimed that they have access to the complete database of Unacademy and decided to leak only users' accounts at this point of time, Cyble said.

The cyber intelligence firm added that further leaks are expected in the near future.

"On May 3, 2020, Cyble Inc discovered that a threat actor had begun to sell an Unacademy user database containing 20 million accounts for USD 2,000. Unacademy is India's largest online learning platform. This data breach apparently took place in January 2020," Cyble claimed.

When contacted, Unacademy co-founder and Chief Technology Officer Hemesh Singh said the company has been closely monitoring the situation and claimed that no sensitive information such as financial data or location has been breached.

"As per our internal investigations, e-mail data of around 11 million users has been compromised as against 22 million stated in reports. This is on account of only around 11 million e-mail data of users available on the Unacademy platform," Singh said.

He said the company is following stringent encryption methods and making it highly implausible for anyone to decrypt passwords.

"We also follow an OTP-based login system that provides an additional layer of security to our users. We are doing a complete background check and will be addressing any potential security loophole to further bolster our efforts of ensuring a far more robust security mechanism. We are in communication with our users to keep them updated on the progress," Singh said.

Facebook, General Atlantic, Sequoia India, Flipkart CEO Kalyan Krishnamurthy, and Nexus Venture Partners have invested in the company.

According to Cyble, this breach can have an impact on security of other companies as well.

"Cybercriminals are always on the lookout for such breaches and utilise them for credential stuffing attacks. We have seen accounts/records with domain names from Infosys, TCS, Cognizant, Reliance Industries, HDFC, Accenture, ICICI, SBI, Canara Bank, Bank of Baroda, Punjab National Bank and several other large organisations," Cyble said.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: May 07 2020 | 9:21 PM IST

Next Story