https://ia.acs.org.au/article/2026/more-than-1m-caught-in-mathspace-data-breach.html

Australian ed-tech provider Mathspace has confirmed a significant data breach affecting more than 1.07 million students, teachers, parents and guardians across Australia and New Zealand, after attackers exploited a known software vulnerability that the company had failed to patch for more than three weeks. The breach centred on Metabase, an internal reporting tool used by Mathspace, which was accessed without authorisation between 10 and 27 August this year. A security patch for the vulnerability had been publicly available since 6 August, just four days before the attacker first gained access, but a breakdown in Mathspace’s internal vulnerability notification processes meant the update went unactioned until 29 August. The company confirmed the breach on 3 September and began notifying its approximately 3,400 Australian school clients the following day. The company issued a public apology, stating the company was taking steps to prevent similar incidents in future and that it was investigating why the initial security advisory had not been escalated internally.

The stolen data included names, email addresses, usernames, user IDs, user types, countries, time zones, email verification statuses, and login and registration dates. Mathspace confirmed that no academic records, passwords, authentication tokens or data linking individual accounts to specific schools was taken, though it cautioned that users with identifiable email domains could potentially be linked back to their institutions.

The breach illustrated the difficulty of keeping on top of an ever-growing list of vulnerabilities and organisations should move away from reactive patching toward a risk-based approach that weighs factors such as whether a vulnerability is already being actively exploited, whether the affected system is internet-facing, and what data it holds. Metabase separately disclosed that fewer than 3% of its cloud customers were compromised before the patch could be applied, with some self-hosted customers also affected. Mathspace has since taken the compromised system offline, engaged cybersecurity authorities and is notifying affected individuals, while the identity of the attacker remains unknown and no ransom demands have been publicly confirmed.

Discover more from Edwin Kwan

Subscribe now to keep reading and get access to the full archive.

Continue reading