Data Breaches

Mathspace Data Breach Exposes Over 1 Million People

Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.

Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.

Mathspace, an online mathematics program for students, has disclosed a data breach that impacts over 1 million individuals.

The incident, it says, was discovered last week, roughly three weeks after hackers compromised its self-hosted Metabase instance using a known vulnerability.

The security defect, tracked as CVE-2026-72898 (CVSS score of 10/10) and described as an SQL injection issue, was patched on August 6, after it had been exploited in the wild as a zero-day.

Shortly after the patches were released, the notorious extortion group ShinyHunters claimed responsibility for hacking Metabase.

Mathspace failed to escalate Metabase’s critical advisory to prioritize patching and upgraded its instance on August 29, more than two weeks after hackers hit it.

“Our investigation identified unauthorised access dating back to 10 August 2026, Australian Eastern Standard Time. We confirmed that information was downloaded from our Australian reporting database on 27 August,” Mathspace says in an incident notice.

Advertisement. Scroll to continue reading.

Furthermore, Mathspace did not complete the compromise checks Metabase had recommended, and did not identify the intrusion upon applying the update.

“We are investigating why the initial advisory was not escalated and why those checks were not completed sooner. We are changing both processes as part of our incident response,” the online platform says.

Mathspace has taken its Metabase instance offline, revoked API keys, disabled the database access accounts, changed passwords, and exported the logs for investigation.

The data breach impacts 1,079,819 students, teachers, staff, and parents/guardians from Australia and New Zealand.

Hackers downloaded names, user IDs, usernames, email addresses, email verification status, time zone, country, date joined, and last login and active dates.

“No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools,” Mathspace says.

The platform warns that the threat actors may use the stolen information to mount phishing attacks, urging the potentially affected individuals to treat with extreme caution any unsolicited communication containing accurate references to the incident.

Mathspace reported the incident to the relevant authorities in Australia and, over the weekend, started notifying the potentially affected individuals.

Related: Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

Related: 153 Million Driver License Images Offered on Dark Web

Related: Ransomware Gang Claims Nutex Health Data Breach

Related: 9.5 Million Impacted by Aesto Health Data Breach

Related Content

Data Breaches

The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.

Data Breaches

Hackers stole personal and health information from the healthcare technology company’s AWS infrastructure.

Data Breaches

The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems.

Data Breaches

FulcrumSec says it stole over 80 GB of data from Manchester Airports Group and plans to leak it online.

Data Breaches

The Rhysida ransomware group has claimed the exfiltration of over 5TB of data, including personal information and credentials.

Data Breaches

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.

Data Breaches

Nutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration.

Data Breaches

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version