Overview
- Mathspace confirmed late Thursday that unauthorised parties had accessed its internal reporting system and that attackers downloaded data from its Australian reporting database on August 27 after gaining access as early as August 10.
- A total of 1,079,819 people in Australia and New Zealand were affected and the stolen fields include names, email addresses, user IDs and account metadata while passwords, SSO tokens and academic records were not exposed.
- The attackers exploited a Metabase vulnerability first disclosed on August 6 that Mathspace’s internal alerting process failed to catch and the company says it did not complete recommended compromise checks when it updated the system.
- Mathspace took the compromised Metabase instance offline on September 3, revoked API keys and changed database credentials, notified Australian and New Zealand cyber and privacy authorities, and began contacting affected schools and individuals.
- Security outlets link the incident to a wider wave of Metabase compromises that have hit other organisations and Mathspace warns the leaked contact details raise the risk of phishing while its post-incident remediation and process review continue.