More than a million students, teachers, parents, and guardians have been caught up in a data breach at Australian learning provider Mathspace.
The company confirmed the incident on 3 September after security staff discovering “unauthorised parties” had gained admin access to their internal reporting tool Metabase.
The company subsequently found the attacker had downloaded personal information belonging to students, their parents or guardians, teachers and Mathspace staff.
Mathspace has not disclosed how many of its approximate 3,400 Australian school clients had their data exposed but said 1,079,819 people were “affected”.
“We're truly sorry this happened and are taking steps to prevent similar breaches in the future,” read a blog post by Mathspace chief technical officer Alvin Savoy.
Mathspace began notifying affected schools on 4 September and later confirmed the breach affected people in both Australia and New Zealand.
When asked whether it had received any ransom demands following the incident, Mathspace directed Information Age to its existing blog post.
“We have no evidence so far that the data has been published, distributed, sold or otherwise misused,” read the blog post.
“Identity of the attacker remains unknown as of this writing.”
What was stolen?
The stolen data included first names, last names, email addresses, countries and time zones.
It also included user IDs, usernames, user types, email-verification statuses, last active and login dates, and registration dates.
Mathspace stressed not every data field was held for every person affected.
The company added that no academic records, results, passwords, or other authentication tokens were exposed.
Nor did the stolen data contain records linking individual user accounts to their schools.
However, Mathspace warned that accounts could potentially be linked to schools where users have identifiable email domains.
Danny Jenkins, chief executive of endpoint security company ThreatLocker, said the exposed information could be used to create “convincing spearphishing campaigns” impersonating Mathspace or a school.
“There is also a long-term issue within the data,” Jenkins told Information Age.
“A student in Year 12 may become a much more valuable target within a few years, and personal information can remain useful to criminals for a very long time.
“Information from this breach can also be combined with data from other breaches to build a much more detailed profile of an individual.”
Mathspace has urged those impacted to partake in basic scam awareness measures, such as exercising caution for unexpected messages and using unique passwords across their accounts.
Unpatched software exploited
The attacker accessed Mathspace’s Metabase between 10 August and 27 August, according to the company.
The hacker gained access by exploiting a known, already-mitigated vulnerability that was left unpatched for more than three weeks.
Although Metabase published a security advisory and patches for the issue on 6 August, a lapse in Mathspace’s vulnerability-notification processes meant the issue went unactioned until 29 August.
Mathspace performed a review of its access logs, and on 3 September confirmed a breach had occurred before the update was applied.
“Once a serious vulnerability becomes public, attackers can move very quickly to create an exploit and start probing for unpatched systems,” said Jenkins.
“In this case, the software company released patched versions on August 6 and Mathspace identified unauthorised access beginning just four days later.”
Mathspace has since taken the compromised reporting system offline, contacted cybersecurity authorities and begun notifying affected individuals.
“We are investigating why the initial advisory was not escalated and why [additional compromise] checks were not completed sooner,” the company said.
‘Whack-a-mole’ patching won’t cut it
Steve Hunter, director of engineering for Asia-Pacific at cybersecurity company Arctic Wolf, said the incident highlighted how difficult it can be for organisations to “keep on top of software vulnerabilities”.
“Organisations can be forced to make decisions about what to prioritise without having the full picture,” said Hunter.
"Rather than playing whack-a-mole every time a new vulnerability appears, organisations need to take a more risk-based approach.
“Consider whether a vulnerability is already being exploited by attackers, whether the affected system is exposed to the internet, what information it holds or can access, and the potential impact if it is compromised.”
Metabase said fewer than 3 per cent of its cloud customers were “compromised” as a result of the vulnerability before they could patch it.
It also said “some open source users and self-hosted customers with publicly accessible Metabase instances” were affected.
Information Age has asked Metabase whether any other compromises of unpatched Metabase instances have emerged over the past month but had not received a response before publication.