Site icon techcoffeehouse.com

Mathspace Breach Exposes Data of 1 Million Users

Advertisements

Online maths learning platform Mathspace has confirmed a data breach affecting 1,079,819 students, parents, guardians, teachers and staff across Australia and New Zealand, after attackers exploited a security flaw in an internal reporting tool.

Mathspace said attackers gained administrator access to its self-hosted installation of Metabase, used for internal reporting, without a legitimate login. A critical security advisory for the flaw had been issued on 6 August, four days before the intrusion began. The company later acknowledged that its vulnerability-notification process failed to escalate the warning in time. Data was downloaded from the company’s Australian reporting database on 27 August, and the breach was confirmed on 3 September.

Names, emails and account details exposed

The exposed data included names, usernames, user IDs, email addresses, countries, time zones, email-verification status, and account activity dates. Mathspace said no academic records, assessment results, passwords, authentication tokens, SSO credentials or API credentials were taken, and that the exposed data did not directly link accounts to schools, though it acknowledged this may be inferable for schools with identifiable email domains.

“We’re truly sorry this happened and are taking steps to prevent similar breaches in the future,” Mathspace chief technology officer Alvin Savoy said in a company blog post. “Protecting the information entrusted to us by students, families and schools is our responsibility.” The company has since shut down the affected reporting system and is notifying schools and cyber authorities in both countries.

Security experts flag risks for internal tools

Commenting on the breach, Takanori Nishiyama, Senior Vice President APAC and Country Manager, Japan at Keeper Security, said internal reporting and analytics tools often sit outside the patch cycles and access controls applied to external-facing systems. He pointed to Keeper Security research finding that 46% of organisations in APAC report significant cloud security gaps, and cautioned that stolen data tied to children can hold value for years, since fraud committed in a minor’s name may go unnoticed until they apply for credit or housing as adults.

Mathspace and security researchers are advising affected users to change any reused passwords, set unique passwords for each account, enable multi-factor authentication where possible, and treat unsolicited messages referencing the platform or a child’s school with caution.

Author

Exit mobile version