More than one million people have been affected by a data breach at online maths learning platform Mathspace after attackers accessed an internal reporting system and downloaded personal information belonging to students, school staff and parents or guardians.
Mathspace said 1,079,819 people were affected by the incident, which was limited to individuals in Australia and New Zealand. The company is used by thousands of schools in Australia, New Zealand, the United States and the UK.
The attackers exploited a vulnerability in a self-hosted installation of Metabase, the software Mathspace uses for internal reporting. The flaw enabled them to obtain administrator access without a legitimate login, according to chief technology officer Alvin Savoy.
Mathspace said the intruders first accessed its systems on 10 August and downloaded data from its Australian reporting database on 27 August. The breach was confirmed on 3 September.
What was exposed in the Mathspace breach
The company said the stolen information did not include passwords or password hashes, authentication tokens, single sign-on credentials or API credentials. Academic records, learning activities, results and assessment records were also not accessed.
Mathspace said the data did not contain records directly linking user accounts to individual schools. However, it warned that accounts associated with identifiable school email domains could potentially be linked to an institution.
In a statement, Mr Savoy said unauthorised parties had accessed the reporting system and downloaded information relating to students, their parents or guardians and school staff. Mathspace employees were also among those affected.
The company has warned those caught up in the breach to be alert to suspicious account activity, including unexpected changes to account details and password-reset messages. The stolen information could be used in targeted attempts to obtain further details or gain access to other accounts.
Metabase systems targeted in wider hacking campaign
The Mathspace incident follows breaches involving Metabase installations at several other organisations. Attackers have been exploiting a critical SQL injection vulnerability to gain administrator access to customer systems and extract data.
Other reported victims include laptop manufacturer Framework and online form-building service Tally. Trezor also said the number of people affected after attackers breached its shipping and logistics provider, ShipMonk, had risen from almost 14,000 to 81,000.
ShipMonk has received extortion emails from the ShinyHunters group, although Trezor has not attributed its breach to a particular threat actor. ShinyHunters added Metabase to its dark web leak site on 11 August.
Mathspace said it had secured the affected system after identifying the breach and was notifying those whose information was involved.
