Skip to content
Vulnerability exploitContained

Mathspace Metabase breach (1.08 million students, staff and parents)

Online mathematics learning platform Mathspace disclosed that attackers exploited a vulnerability in its self-hosted Metabase reporting system to download contact data on 1,079,819 students, staff, parents and guardians in Australia and New Zealand.

Victim
Mathspace
records
1.1M
users
1.1M

On 7 September 2026, Mathspace, an online mathematics learning platform founded in Sydney and used by schools in Australia, New Zealand, the United States and the United Kingdom, disclosed a data breach affecting 1,079,819 people, including students, school staff, parents and guardians.

The company said attackers exploited a security vulnerability in Metabase, a self-hosted internal reporting and analytics tool, which let them obtain administrator access without a legitimate login. The initial access dates back to 10 August 2026, data was downloaded on 27 August, and Mathspace confirmed the breach on 3 September. Only residents of Australia and New Zealand were affected.

What was exposed

The stolen data consisted of names and contact information and, in some cases, school affiliations. Mathspace said passwords, authentication credentials, academic records and assessment data were not taken. The company notified affected users and advised them to watch for suspicious activity. Reporting noted that the intrusion matched a wider pattern of Metabase exploitation against several companies, which some researchers linked to ShinyHunters, although the attack was not definitively attributed.

Why it matters

Internal business intelligence tools are often connected directly to production databases but receive less hardening and patching attention than customer-facing systems. For an education provider, a single exposed reporting server was enough to reveal data about more than a million people, a large share of them minors.

Timeline

  1. Attackers gain administrator access to Mathspace's self-hosted Metabase reporting system without a legitimate login.

  2. Data is downloaded from the reporting system.

  3. Mathspace confirms the breach.

  4. The breach, affecting 1,079,819 people, is publicly reported.

Sources

  1. bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/
  2. privacyguides.orghttps://www.privacyguides.org/news/2026/09/11/data-breach-roundup-sep-4-10-2026/

Related incidents