Published 7 hours ago • loading... • Updated 2 hours ago
‘Truly sorry’: Student details exposed in hack
Hackers accessed an unpatched reporting system and stole names, usernames and email addresses, while Mathspace said no passwords or academic records were exposed.
On Thursday, online learning platform Mathspace confirmed a data breach affecting 1,079,819 users across Australia and New Zealand. Unauthorised parties exploited a security vulnerability between August 10 and August 27, accessing names, usernames, and email addresses.
Hackers gained administrator access because a security patch had not been installed on the reporting software. Mathspace subsequently took the compromised system offline and notified education departments and Authorities across Australia and New Zealand.
Chief technology officer Alvin Savoy stated customer passwords, academic records, and SSO credentials remained secure. An account does not need to be active for information retained in the reporting database to be affected, he added.
Mathspace has begun contacting affected individuals and warned that stolen information can facilitate impersonation attempts. The company said it has "no evidence so far" that the data has been published or sold.
Steve Hunter, director of engineering for APAC at Arctic Wolf, said organisations need a "risk-based approach" rather than "Whack-a-Mole" responses to vulnerabilities. Hunter argued education providers must prioritize identifying systems and software to mitigate future risks.