Online math learning platform Mathspace has disclosed a data breach affecting more than 1 million students, parents, guardians, and school staff. Attackers compromised the company’s internal Metabase reporting system and stole personal information from users in Australia and New Zealand.
Founded in Sydney in 2010, Mathspace is used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom. Company statistics reported in 2023 listed 3,432 schools in Australia and 3,557 schools internationally.
Mathspace Chief Technology Officer Alvin Savoy said in a blog post that an unknown attacker gained unauthorized access to the company’s systems and downloaded personal data belonging to students, their parents and guardians, school staff, and Mathspace employees.
“On September 3, 2026, we confirmed that an unauthorized third party had accessed the internal reporting system used by Mathspace and downloaded information about students, their parents, guardians, and school staff. Mathspace staff records were also affected,” Savoy said.
“The attacker exploited a security vulnerability in a self-hosted installation of Metabase, a software we use for internal reporting. This vulnerability allowed the attacker to gain administrative access to that system without a legitimate login.”
Mathspace confirmed the data breach on September 3, but the attackers first accessed the compromised system on August 10. They later downloaded information from Mathspace’s Australian reporting database on August 27.
According to Savoy, the incident affected only students, parents, guardians, and school staff in Australia and New Zealand. The stolen data did not include passwords, educational backgrounds, academic records, or learning information. However, attackers may be able to associate some affected accounts with specific schools, particularly when users have identifiable school email domains.
“A total of 1,079,819 students, staff and parents were affected. Only people in Australia and New Zealand were affected,” Savoy said.
“Academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, and API credentials are not exposed. Exposed data does not include records linking user accounts to schools. However, we understand that this may be possible for schools with identifiable email domains.”
Mathspace is warning affected users that criminals could use the stolen information in phishing attacks or other targeted scams. Students, parents, and school staff should watch for suspicious account activity, unexpected password-reset messages, and requests to update personal or login information.
ShinyHunters claims Metabase data breach campaign
The Mathspace incident is part of a broader series of attacks targeting Metabase installations at organizations around the world.
As previously reported by BleepingComputer, attackers exploited a critical Metabase SQL injection vulnerability to obtain administrator access. They then infiltrated customer environments and stole data from compromised reporting systems.
Trezor disclosed on August 13 that attackers had stolen information belonging to approximately 14,000 customers after breaching ShipMonk, the company’s shipping and logistics provider. The number of people potentially affected later increased to approximately 81,000.
Although Trezor has not attributed the attack to a specific threat actor, BleepingComputer learned that ShipMonk received extortion emails from the ShinyHunters data extortion group. ShinyHunters also added the stolen Metabase data to its dark web leak site on August 11.
Other organizations affected by the Metabase hacking campaign include laptop manufacturer Framework and online form creation platform Tally. Both companies disclosed data breaches after their Metabase instances were compromised.
ShinyHunters has also been linked to breaches affecting more than a dozen Snowflake customers, Salesloft Drift and Salesforce campaigns targeting hundreds of Salesforce customers, and attacks exploiting a zero-day vulnerability in Oracle PeopleSoft that affected more than 100 businesses.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



