Mathspace chief technology officer Alvin Savoy said in a blog post that unknown attackers first gained access to the company's systems on August 10 and downloaded data from its Australian reporting database on August 27. The theft was confirmed on September 3.
“Attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting,” Savoy wrote. “The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login.” ABC News reported the system was accessed during a period when a security patch had not been installed.
A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined, the company said. Exported data included user IDs, usernames, first and last names, email addresses, countries, time zones, user types, email-verification status, last-active date, last-login date and date joined — though not every affected person had all fields stolen.
Mathspace stressed that no academic records, learning activities, results, assessment records, passwords, authentication tokens, SSO credentials or API credentials were exposed, and that the data did not include records linking user accounts to their schools. However, Savoy noted that for schools with identifiable email domains, attackers may be able to make that link.
“We’re truly sorry this happened and are taking steps to prevent similar breaches in the future,” the company said. The compromised reporting system has been taken offline. Mathspace said it has contacted schools, cybersecurity authorities and education departments, and is now contacting affected individuals. It said it does not yet know who was responsible and has found “no evidence so far” that the stolen information has been published, shared or sold.
Savoy warned affected students and staff that attackers may target them using the stolen data, and advised watching for suspicious account-related activity such as changes to account details and password-reset messages. The company urged users to check unexpected messages independently, avoid disclosing passwords or verification codes in response to a message, and use a unique password for each account. Suspicious messages or activity can be reported to data-breach-response@mathspace.co.
The breach adds to a string of incidents involving Metabase instances at companies worldwide over the past month. BleepingComputer previously reported that threat actors exploited a critical Metabase SQL injection zero-day vulnerability to breach customer instances and steal data after gaining administrator access; the Metabase breaches have been claimed by the ShinyHunters threat group, according to the publication. Separately, hardware wallet maker Trezor revealed on August 13 that attackers stole data on nearly 14,000 customers after hacking its shipping and logistics provider ShipMonk, and warned on Friday that the number of affected individuals now reaches 81,000 customers.
Steve Hunter, director of engineering, APAC at cybersecurity firm Arctic Wolf, said the incident highlighted how difficult it can be for organisations to keep on top of software vulnerabilities. “Rather than playing ‘Whack-a-Mole’ every time a new vulnerability appears, organisations need to take a more risk-based approach,” he said. “The priority should be knowing what systems and software you have, understanding where the biggest risks sit, and having a clear process for acting when a critical security warning comes through.”