Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-08 ยท updated: 2026-09-08 ยท tags: [incident, breach, education, australia, metabase, shinyhunters] ยท confidence: high ยท affected_sectors: [education, technology] ยท au_impact: true

Mathspace Discloses Data Breach Affecting Over 1,079,819 People

Mathspace, a Sydney-founded online maths learning platform used by thousands of schools across Australia, New Zealand, the United States and the United Kingdom, disclosed that unknown attackers exploited a critical Metabase SQL-injection vulnerability in its self-hosted reporting environment to obtain administrator access without a legitimate login and download personal information on students, parents/guardians and school staff from its Australian reporting database.

Attribute Detail
Access began 10 August 2026
Data downloaded 27 August 2026
Breach confirmed 3 September 2026
Total affected 1,079,819 (Australia and New Zealand only)
Vector Metabase SQL injection (critical)
Source BleepingComputer โ€” Tier 2/4

Mathspace states no academic records, passwords or hashes, authentication tokens, SSO credentials or API credentials were exposed, but warns that for schools with identifiable email domains attackers may be able to link accounts, and advises watching for phishing or password-reset activity. The incident is part of a Metabase campaign that has also compromised Trezor, Framework and Tally, with the ShinyHunters-linked threat actor pursuing multiple Metabase victims โ€” a canary for Australian organisations running exposed Metabase instances. It squarely engages the OAIC Notifiable Data Breaches scheme.

Related Pages

Source