Skip to main content
Emerging ThreatsData Breaches

Mathspace Breach Exposes Data of 1 Million People

A calm school hallway with students, teachers, and scattered desks, with a computer on a table in the foreground.

A total of 1,079,819 people — students, school staff, and parents or guardians in Australia and New Zealand — had personal information stolen after attackers breached an internal Mathspace reporting system, the company disclosed.

Mathspace: who it serves and what the company says was taken

Founded in Sydney in 2010, Mathspace told users it serves thousands of schools across Australia, New Zealand, the United States and the United Kingdom, citing company statistics from 2023 that list 3,432 schools in Australia and 3,557 abroad. In a Saturday blog post Mathspace CTO Alvin Savoy wrote that “unauthorised parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff. Mathspace staff records were also affected.”

Savoy stated that the incident affected only people in Australia and New Zealand and that the company confirmed the theft on 3 September 2026. He supplied the exact affected figure: “A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected.”

Metabase vulnerability and the intrusion timeline

Mathspace says the attackers “exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting. The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login,” Savoy wrote. According to the company, attackers first gained access to the compromised systems on 10 August and downloaded data from Mathspace’s Australian reporting database on 27 August.

The blog post frames the breach as part of an exploitation of a critical flaw in customer-hosted Metabase instances: BleepingComputer reported that threat actors used a Metabase SQL injection zero-day to gain administrator access and steal data from multiple customer deployments.

What Mathspace says was not exposed, and remaining risks

Savoy emphasised the scope of what the company believes was not taken: “No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed.” He added that attackers did not steal credentials, although “in some cases they may have been able to link some impacted accounts to their schools.” Elsewhere Mathspace stated that “the exposed data did not include records linking user accounts to their schools. However, for schools with identifiable email domains, we understand this may be possible.”

Despite those exclusions, Mathspace warned that affected students and school staff “may” be targeted using the stolen data and advised them to monitor for “suspicious account-related activity, such as changes to account details and password-reset messages.”

Metabase incidents, other victims, and groups claiming responsibility

This disclosure follows a string of incidents after attackers exploited Metabase customer instances. BleepingComputer noted that several companies have disclosed breaches following Metabase compromises: Trezor reported attackers stole data on nearly 14,000 customers after a breach of its shipping and logistics provider ShipMonk; laptop maker Framework and online form-builder Tally also disclosed data theft tied to hijacked Metabase instances.

Some breaches involving Metabase have been linked publicly to posts and extortion activity by the ShinyHunters extortion gang: ShinyHunters added Metabase to its dark web leak site on 11 August, and BleepingComputer reported that ShipMonk received extortion emails from ShinyHunters. The Mathspace post does not assign a named actor to this specific incident; it describes exploitation of the Metabase vulnerability and the resulting data exfiltration.

What this means for students, school staff, and school IT teams

  • Students, parents and school staff: Mathspace’s notice is direct — watch for unusual account-related messages, changes to account details, and password-reset notices. The company warned that the stolen contact and identity data could be used to target individuals.
  • School IT teams and administrators: the attack underscores risk in self-hosted analytics and reporting tools. The incident timeline shows attackers moved from initial access on 10 August to data downloads on 27 August; Mathspace attributes the breach to a Metabase vulnerability that allowed administrative access without a legitimate login.
  • Security practitioners: the wider reporting notes that once attackers obtain valid administrative access prevention measures become far less effective. The source observes that “once attackers are using valid credentials, prevention drops sharply,” a point highlighted by a referenced Blue Report 2026 measurement of defenses.

Mathspace’s disclosure places one clear, immediate obligation on the company and on other organisations running self-hosted Metabase: confirm whether they are patched, audit administrator access, and notify impacted communities. For the nearly 1.08 million people named in Mathspace’s assessment, the practical next steps are vigilance and scrutiny of account communications — exactly what the company advised in its blog post.

Original reporting: https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/