← Back to Tech & Science

Mathspace Confirms Data Breach Affecting Over 1 Million Users in Australia and New Zealand

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SYDNEY — Mathspace, a leading educational technology provider serving schools across Australia and New Zealand, confirmed on Monday that a cyberattack has compromised the personal data of more than one million students, staff members, and parents. The breach was discovered after attackers exploited a security vulnerability in the company's internal reporting system to gain unauthorized administrative access.

The incident involved Mathspace's self-hosted installation of Metabase, an analytics tool used for internal data visualization. Security researchers identified that the attackers leveraged a flaw in this specific configuration to bypass standard authentication protocols. This allowed the intruders to assume administrator privileges without providing legitimate login credentials, granting them broad access to sensitive information stored within the platform.

Mathspace stated that the compromised data includes names, email addresses, and other personal details associated with user accounts. The company has not yet disclosed whether financial information or passwords were accessed, though it confirmed that no evidence of unauthorized transactions has been found to date. The breach affects educational institutions in both Australia and New Zealand where Mathspace's digital learning platform is deployed.

In response to the incident, Mathspace immediately initiated an investigation with external cybersecurity firms and notified relevant regulatory authorities in both countries. The company has since patched the vulnerability in its Metabase installation and implemented additional security measures to prevent similar exploitation. All affected users have been advised to monitor their accounts for suspicious activity and to change their passwords as a precautionary measure.

The breach highlights ongoing challenges faced by educational institutions regarding the security of third-party software integrations. While Mathspace maintains that its core learning platform remained uncompromised, the incident underscores the risks associated with self-hosted administrative tools that may not receive immediate updates from vendors. The company emphasized its commitment to transparency and is working closely with affected schools to mitigate any potential impact on students and families.

Questions remain regarding the duration of the attackers' access and the full extent of the data exfiltrated. Mathspace has indicated that a detailed forensic report will be released in the coming days, which may provide further clarity on the timeline of the intrusion. As the investigation continues, officials are urging schools to review their own security protocols for similar internal reporting systems to ensure they are not vulnerable to the same exploitation method.

The company has established a dedicated support line for affected users and is cooperating with law enforcement agencies to trace the origin of the attack. No ransom demands have been reported in connection with the breach, and Mathspace has not identified the group responsible for the intrusion.

Discussion

0 / 2000