The personal data of more than one million students, parents, guardians and school staff in Australia and New Zealand has been exposed during a cyber security attack on online learning platform Mathspace.
“Unauthorised parties” accessed an internal reporting system in August to swipe names, email addresses and user IDs, among other information.
Mathspace staff records were also affected.
Know the news with the 7NEWS app: Download today Arrow
“We’re truly sorry this happened and are taking steps to prevent similar breaches in the future,” the company’s chief technology officer Alvin Savoy said.
“Protecting the information entrusted to us by students, families and schools is our responsibility.”
Savoy said there is no evidence the data has been “published, distributed, sold or otherwise misused”.
“Identity of the attacker remains unknown,” he said.
Savoy said customer passwords, academic records and results, single sign-on tokens and other customer authentication credentials were not exposed during the digital breach.
The personal data of more than one million students, parents, guardians and school staff in Australia and New Zealand has been exposed. Credit: 7NEWS
Hackers were able to obtain administrator access to software used for internal reporting as early as August 10, before names and other data was downloaded on August 27.
The breach was confirmed and the compromised system taken offline on Thursday.
Authorities in Australia and New Zealand have been alerted, and state and territory education departments have been informed.
“A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected,” Savoy said.
Former users may be impacted too, because an “account does not need to be currently active for information retained in the reporting database to be affected”.
A ‘warning’ for every Australian school
Digidentity managing director Fred Slikker said the latest breach should be a “warning” for every Australian school using third-party learning platforms.
“Outsourcing a digital service doesn’t outsource responsibility for student identity data,” Slikker told 7NEWS.com.au.
“Schools need to know where providers copy that information, including into internal reporting systems, who can access it and how quickly critical security updates are applied.”
He said contracts should include enforceable requirements to prove that controls are working.
“Children and parents shouldn’t be left to manage risks created by systems selected on their behalf,” he said.
Steve Hunter, director of engineering at cybersecurity and AI company Arctic Wolf, said the Mathspace breach shows organisations need to take “a more risk-based approach”, rather than “playing whack-a-mole every time a new vulnerability appears”.
“This is particularly important in the education sector, where schools, universities and education technology providers can hold large volumes of information relating to students, parents, teachers and staff across a wide range of systems and third-party platforms,” Hunter said.
Lingering threat from data breaches
Savoy said the “incident is real” but that not every message referring to it will be genuine.
Mathspace said caution should be shown and that any email or call relating to the breach should be checked independently.
It was only in late August that experts warned about the lingering threat Australians face in the wake of recent cyberhacks.
“Stolen information can be retained, traded and combined with data from future incidents,” Slikker said.
“Australians affected by a breach therefore face a continuing risk of impersonation and identity misuse, even after they have changed their password or replaced a compromised card.”
What experts want Aussies to know about recent cyberattacks
4 min read
This is the threat that scares Australia’s former cyber chief most
3 min read