Mathspace Discloses Data Breach Affecting Over 1,079,819 People
Mathspace, a Sydney-founded online maths learning platform used by thousands of schools across Australia, New Zealand, the United States and the United Kingdom, disclosed that unknown attackers exploited a critical Metabase SQL-injection vulnerability in its self-hosted reporting environment to obtain administrator access without a legitimate login and download personal information on students, parents/guardians and school staff from its Australian reporting database.
| Attribute | Detail |
|---|---|
| Access began | 10 August 2026 |
| Data downloaded | 27 August 2026 |
| Breach confirmed | 3 September 2026 |
| Total affected | 1,079,819 (Australia and New Zealand only) |
| Vector | Metabase SQL injection (critical) |
| Source | BleepingComputer โ Tier 2/4 |
Mathspace states no academic records, passwords or hashes, authentication tokens, SSO credentials or API credentials were exposed, but warns that for schools with identifiable email domains attackers may be able to link accounts, and advises watching for phishing or password-reset activity. The incident is part of a Metabase campaign that has also compromised Trezor, Framework and Tally, with the ShinyHunters-linked threat actor pursuing multiple Metabase victims โ a canary for Australian organisations running exposed Metabase instances. It squarely engages the OAIC Notifiable Data Breaches scheme.
Related Pages
- Shinyhunters โ the group linked to the wider Metabase campaign
- Cisa Adds Metabase Sql Injection Flaw Cve 2026 72898 To Known Exploited Vulnerab โ the Metabase KEV flaw