More than one million students, parents, guardians and teachers across Australia and New Zealand have been caught up in a major data breach after hackers accessed an internal Mathspace system and stole personal details.
Mathspace is an online maths learning platform used by schools to deliver lessons, set work and track student progress.
The education platform revealed that 1,079,819 people were affected after “unauthorised parties” gained access to an internal reporting system between August 10 and August 27 when a security patch had not been installed.
In a blog post by chief technical officer Alvin Savoy, Mathspace confirmed the stolen information included details such as names, usernames, email addresses and other account information.
The company stated not every affected person had every type of data exposed.
The breached details may include user ID, username, first name, last name, email address, country, time zone, user type, email verification status, last active date, last login date and date joined.
Mathspace stated more sensitive material was not exposed.
It confirmed no academic records, learning activities, results, assessment records, password hashes, authentication tokens, single sign-on credentials or API credentials were accessed.
“The exposed data did not include records linking user accounts to their schools,” Mr Savoy said.
“However, for schools with identifiable email domains, we understand this may be possible.”
The company said it did not yet know who was behind the attack and had “no evidence so far” that the stolen data had been published, shared or sold.
Mathspace warned that even limited personal information could still create serious risks for those affected.
“Names, email addresses and account details can make impersonation attempts more convincing,” Mr Savoy said.
“Someone may use them to send a message that appears to come from Mathspace, your school or another organisation you know.”
People affected have been urged to be careful with unexpected emails and messages, especially those asking for passwords, login details or verification codes.
Mathspace also advised users to contact organisations through the official details listed on their websites if they were unsure whether a message was genuine.
“Watch for unusual account activity, pay attention to unexpected password-reset emails or changes to your account details,” Mr Savoy said.
The company also warned anyone who had reused their Mathspace password on another service should change that password elsewhere and replace it with something unique.
Mathspace stated it had notified affected schools, cyber authorities and education departments in Australia and New Zealand and was now contacting impacted individuals.
People who want to check whether their data was involved can contact the company directly.
The internal reporting service involved in the breach has since been shut down.
“We’re truly sorry this happened and are taking steps to prevent similar breaches in the future,” Mr Savoy said.
“Protecting the information entrusted to us by students, families and schools is our responsibility.”
Arctic Wolf director of engineering for APAC Steve Hunter, said the Mathspace incident highlighted how difficult it could be for organisations to keep on top of software vulnerabilities.
“Rather than playing ‘Whack-a-Mole’ every time a new vulnerability appears, organisations need to take a more risk-based approach,” Mr Hunter said.
He said that mattered even more in education, where schools and technology providers could hold large volumes of information on students, parents, teachers and staff.
“The priority should be knowing what systems and software you have, understanding where the biggest risks sit and having a clear process for acting when a critical security warning comes through,” Mr Hunter said.