Mathspace Breach Hits 1 Million Students and Teachers

A data breach at online learning platform Mathspace has affected more than a million users across New Zealand and Australia, New Zealand's Ministry of Education told school leaders, in the first of three breaches now prompting warnings from cybersecurity researchers.

Key facts

  • What happened: Mathspace confirmed that attackers downloaded information on students, parents or guardians, and school staff

  • Scale: More than one million users across New Zealand and Australia, according to the Ministry of Education

  • Data involved: The ministry said the breach may have included private information such as names and email addresses

  • Two more breaches: Health research company Zenith Technology (ZenTech) and payroll provider Thankyou Payroll

  • What to do: Affected users should reset passwords and expect targeted phishing attempts

What happened at Mathspace?

Mathspace confirmed that hackers downloaded information relating to students, their parents or guardians, and school staff. In a special bulletin to school leaders, New Zealand's Ministry of Education said the breach affected more than a million Mathspace users across New Zealand and Australia and may have included private details such as names and email addresses.

Both paid subscriber schools and individuals who signed up for the free version may be affected. The ministry advised schools and individuals to reset passwords and consult their IT administrators, and said Mathspace had alerted the Office of the Privacy Commissioner and the National Cyber Security Centre.

Schools were also pointed to the Privacy Commissioner's guidance, with the ministry noting each school must assess its own obligations under the Privacy Act 2020.

What were the other two breaches?

Police are investigating an incident at health research company Zenith Technology, known as ZenTech, in which a large number of files related to clinical trials may have been stolen. Separately, payroll company Thankyou Payroll told users they had been caught up in a global security breach involving Metabase, an open-source analytics tool.

Why are payroll and health companies such attractive targets?

Because of what their data enables. Ben Van Der Weerd, an undergraduate cybersecurity researcher at Victoria University, said payroll companies hold large volumes of personally identifiable information — data that identifies a specific person, such as a full name, address or tax number — which sells well on criminal marketplaces and fuels further attacks.

Health data is valuable for a different reason. Dr. Abhinav Chopra, a cybersecurity expert at the University of Auckland, said clinical information cannot be changed the way a password or email address can, making the dataset durable and saleable over long periods. He added that health companies are also more likely to pay a ransom.

Chopra noted that the attackers who targeted ZenTech were previously known to use phishing to steal credentials and then move through privileged accounts, while cautioning that he was not claiming that is what happened at ZenTech.

What should smaller organizations take from this?

That the odds have shifted. Chopra argued organizations have long treated the impact of a cyberattack as high but the likelihood as low, and that this assumption no longer holds. His practical advice: get an assessment done, adopt the cheap quick wins first, and build a roadmap for the rest rather than waiting for a complete program.

Source: SecurityBrief New Zealand, originally published by RNZ.