Mathspace, an online mathematics learning platform used by schools in Australia, New Zealand, the United States, and the United Kingdom, disclosed a data breach over the weekend that affected more than 1 million people. According to the company, attackers accessed its internal reporting system and downloaded personal information belonging to school staff, students, and their parents or guardians. The breach impacted 1,079,819 individuals, all located in Australia and New Zealand, with Mathspace staff records also compromised.
The company said in a Saturday blog post that it confirmed the unauthorized access on September 3, 2026. Chief Technology Officer Alvin Savoy explained that attackers exploited a security vulnerability in Mathspace鈥檚 self-hosted installation of Metabase, a software tool used for internal reporting. The flaw allowed the threat actors to obtain administrator access without a legitimate login. The intruders first gained access to the systems on August 10 and downloaded data from the company鈥檚 Australian reporting database on August 27.
Savoy stated that no academic records, learning activities, results, assessment records, passwords, authentication tokens, SSO credentials, or API credentials were exposed. The stolen data also did not include records directly linking user accounts to their schools. However, the company warned that for schools with identifiable email domains, attackers may be able to infer those connections. Mathspace advised affected individuals to remain alert for suspicious account activity, such as unexpected password-reset messages or changes to account details.
Mathspace, founded in Sydney in 2010, reports widespread adoption by schools, citing statistics from 2023 that show 3,432 institutions in Australia and 3,557 abroad using its platform. The company鈥檚 disclosure follows a string of recent incidents involving Metabase instances at other organizations worldwide. BleepingComputer previously reported that threat actors exploited a critical Metabase SQL injection zero-day vulnerability to breach customer systems and steal data after gaining administrator access.
Other companies have disclosed similar breaches tied to compromised Metabase installations, including laptop maker Framework and online form-building platform Tally. In a related incident, cryptocurrency hardware firm Trezor revealed on August 13 that attackers stole data from nearly 14,000 customers following a hack of its shipping provider, ShipMonk, later revising that figure to 81,000 affected individuals. BleepingComputer reported that ShipMonk received extortion emails from the ShinyHunters gang, which added Metabase to its dark web leak site on August 11.
ShinyHunters has been linked to a broader pattern of data theft, including breaches at more than a dozen Snowflake customers, campaigns targeting Salesforce customers through services like Salesloft Drift and Salesforce Aura, and over 100 enterprise victims from exploits of an Oracle PeopleSoft zero-day flaw. The Mathspace breach adds another example of attackers leveraging Metabase vulnerabilities to access sensitive data, though the company has not attributed the incident to a specific group.
More cybersecurity news from TechManNews.





