Sep 7 / Latest News

Mathspace Breach Exposes Data of More Than 1 Million Students, Staff, and Parents

Mathspace has disclosed a major data breach after attackers exploited a vulnerability in its Metabase reporting system, allowing them to steal information belonging to more than 1 million students, staff, and parents across Australia and New Zealand.

Founded in Sydney in 2010, Mathspace is used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom. In a statement published on Saturday, Mathspace CTO Alvin Savoy said that unknown attackers gained unauthorized access to the company's systems and downloaded personal information tied to students, school staff, and their parents or guardians.

Savoy said Mathspace confirmed on September 3, 2026, that attackers had accessed its self-hosted Metabase installation and obtained administrator access by exploiting a security vulnerability. This allowed the threat actors to download data without a legitimate login. Although the breach was discovered in early September, the attackers first gained access on August 10 and downloaded data from Mathspace's Australian reporting database on August 27.

According to Savoy, a total of 1,079,819 people were affected, including students, staff, and parents or guardians. Only individuals in Australia and New Zealand were impacted. No academic records, learning activity data, assessment results, passwords, authentication tokens, SSO credentials, or API credentials were exposed. The stolen data did not include records linking user accounts to their schools, although email domains may allow attackers to infer school affiliation in some cases.

Savoy warned that attackers may attempt to target affected individuals using the stolen information and advised them to watch for suspicious account activity, including changes to account details or password reset messages.

This breach is part of a broader wave of attacks targeting Metabase installations worldwide. Threat actors have exploited a critical SQL injection zero-day vulnerability to gain administrator access and steal data from multiple companies. Recent victims include Trezor, Framework, and Tally. ShinyHunters, an extortion group linked to numerous high-profile breaches, has claimed responsibility for several Metabase-related attacks and added Metabase to its dark web leak site.

ShinyHunters has previously been tied to breaches affecting Snowflake customers, Salesforce-related campaigns, and more than 100 enterprise victims through attacks exploiting an Oracle PeopleSoft zero-day flaw.