Online learning giant Mathspace has disclosed a major security breach targeting its Metabase reporting system, compromising the personal data of over 1 million individuals in Australia and New Zealand.
- Attackers exploited a vulnerability in Mathspace's self-hosted Metabase installation.
- Over 1,079,819 students, staff, and parents were affected.
- The breach is localized to users in Australia and New Zealand.
- Academic records and passwords remain secure; however, personal info was stolen.
Online mathematics learning platform Mathspace has confirmed a significant data breach that has impacted more than one million users. The breach, which targeted the company's internal reporting system, Metabase, has exposed the personal information of students, school staff, and their parents or guardians.
The Anatomy of the Attack
According to Alvin Savoy, Chief Technology Officer at Mathspace, the unauthorized access was confirmed on September 3, 2026. However, the timeline of the intrusion reveals a prolonged period of vulnerability. The attackers first gained access to the systems on August 10 and proceeded to download data from the Australian reporting database on August 27.
The breach occurred due to a security vulnerability in Mathspace's self-hosted version of Metabase. This flaw allowed the threat actors to bypass legitimate login procedures and gain full administrator privileges, enabling them to download sensitive datasets without detection for several weeks.
Why This Matters
BozokMedia analysis shows that this incident is part of a broader, more sophisticated trend where attackers target the software supply chain. By exploiting vulnerabilities in widely used internal tools like Metabase, hackers can gain a foothold in multiple organizations simultaneously, moving from simple data theft to large-scale extortion.
The exploitation of self-hosted software vulnerabilities is becoming a primary vector for large-scale data exfiltration in the EdTech sector.
A Pattern of Global Breaches
The Mathspace incident does not exist in a vacuum. It follows a wave of recent attacks attributed to the ShinyHunters extortion gang, who have been targeting Metabase instances globally. Other notable companies recently impacted by similar vulnerabilities include Trezor, Framework, and Tally.
The scale of these attacks is alarming. For instance, Trezor recently reported that its data breach impact rose to 81,000 individuals after a third-party provider was compromised. This highlights the interconnected nature of modern digital infrastructure and the cascading risks posed by third-party software vulnerabilities.
Historical Background
Founded in Sydney in 2010, Mathspace has grown into a global educational powerhouse, serving thousands of schools across Australia, New Zealand, the United States, and the United Kingdom. This breach marks one of the most significant security challenges in the company's 16-year history.
Frequently Asked Questions
1. Was my academic history or password leaked?
No. Mathspace confirmed that academic records, passwords, authentication tokens, and SSO credentials were not exposed during this breach.
2. Which regions are most at risk?
The breach specifically affected users located in Australia and New Zealand.