Post

Mathspace Discloses Data Breach Affecting Over 1 Million People

Mathspace Discloses Data Breach Affecting Over 1 Million People

Mathspace Discloses Data Breach Affecting Over 1 Million People

🚨 Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. In a Saturday blog post, Mathspace CTO Alvin Savoy stated that unknown attackers gained access to the company’s systems and stole personal information belonging to school staff and students, as well as their parents and guardians.

Details of the Breach

Attackers exploited a security vulnerability in Mathspace’s self-hosted installation of Metabase, software used for internal reporting. This vulnerability allowed attackers to obtain administrator access to that system without a legitimate login. While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace’s Australian reporting database on August 27.

According to Savoy, “A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected.” He added that no academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools. However, for schools with identifiable email domains, this may be possible.

Warning to Affected Individuals

Savoy also warned affected students and school staff that attackers may target them using the stolen data, advising them to watch for suspicious account-related activity, such as changes to account details and password-reset messages.

Broader Implications

This breach adds to a string of other incidents impacting the Metabase instances of multiple other companies worldwide over the last month. As reported by BleepingComputer, threat actors exploited a critical Metabase SQL injection zero-day vulnerability to breach customer instances and steal data after gaining administrator access. Although Trezor has yet to attribute the attack to a specific threat actor or hacking group, BleepingComputer has learned that ShipMonk has received extortion emails from the ShinyHunters extortion gang. ShinyHunters also added Metabase to its dark web leak site on August 11. The list of affected companies in this campaign includes laptop maker Framework and online form-building platform Tally, both of which have disclosed data breaches after their Metabase instances were hijacked.

Conclusion

Stay vigilant and monitor your accounts for any unusual activity!

Read full article

This post is licensed under CC BY 4.0 by the author.