More than 1 million users affected in Mathspace data breach
Summarized by DistantNews. Read the original for the full story.
At a glance
- Mathspace said 1,079,819 people in Australia and New Zealand were affected after attackers accessed an internal reporting system between August 10 and 27.
- Exposed information included names, email addresses and account-related data, but not academic records, passwords, authentication tokens or school-account links.
- The company took the system offline, contacted authorities and schools, and said it had found no evidence that the stolen information had been published, shared or sold.
A data breach at education provider Mathspace affected 1,079,819 people in Australia and New Zealand, including students, school staff and parents. The attackers accessed an internal reporting system between August 10 and August 27, while a security patch remained uninstalled.
Unauthorised parties had accessed an internal reporting system used by Mathspace.
Mathspace said the attackers exploited a vulnerability in its self-hosted software installation. The exposed information included user IDs, usernames, names, email addresses, countries, time zones, user types, email-verification status, last-active dates, last-login dates and joining dates. The company said not every affected person had all of those fields exposed.
The breach did not include academic records, learning activities, results, assessment records, password hashes, authentication tokens, single sign-on credentials or API credentials. Mathspace also said the data did not include records linking user accounts to schools.
We're truly sorry this happened and are taking steps to prevent similar breaches in the future.
The compromised reporting system has been taken offline. Mathspace said it had contacted schools, cybersecurity authorities and education departments and was contacting affected individuals. It said it did not know who was responsible and had found "no evidence so far" that the stolen information had been published, shared or sold.
Protecting the information entrusted to us by students, families and schools is our responsibility.
The company advised users to verify unexpected messages independently, avoid disclosing passwords or verification codes in response to messages, use unique passwords and monitor accounts for unusual activity. Steve Hunter of Arctic Wolf said the incident showed why organizations need a risk-based process for responding to software vulnerabilities, rather than reacting separately to every new warning.
Rather than playing 'Whack-a-Mole' every time a new vulnerability appears, organisations need to take a more risk-based approach.
Originally published by ABC Australia. Summarized and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.