A major security breach at Mathspace has compromised the personal data of over 1 million students, teachers, and parents across Australia and New Zealand. The attack exploited a critical SQL injection vulnerability in Metabase.

  • Over 1,079,819 individuals impacted in Australia and New Zealand.
  • Exploitation of critical SQL injection vulnerability (CVE-2026-72898).
  • Notorious hacking group ShinyHunters claimed responsibility.
  • Academic records and passwords remain uncompromised.

Online mathematics platform Mathspace has confirmed a massive data breach affecting more than 1 million individuals. The incident has sent shockwaves through the educational community in Australia and New Zealand, involving students, educators, staff, and guardians.

The breach originated from a self-hosted Metabase instance. Attackers exploited a critical security defect known as CVE-2026-72898, an SQL injection vulnerability with a maximum CVSS score of 10/10. This flaw was utilized as a zero-day exploit before being patched on August 6.

Why This Matters

BozokMedia analysis shows that this incident highlights a significant failure in incident response and patch management. Despite Metabase issuing a critical advisory, Mathspace failed to escalate the issue or complete recommended compromise checks. The company did not upgrade its instance until August 29, nearly three weeks after the initial compromise, providing a massive window of opportunity for threat actors.

The delay between a patch release and its implementation is the primary window where most catastrophic data thefts occur.

The extortion group ShinyHunters has claimed responsibility for the hack. According to Mathspace's investigation, unauthorized access began on August 10, with a massive data download occurring from their Australian reporting database on August 27. The stolen data includes names, user IDs, email addresses, and login metadata.

Crucially, Mathspace has stated that sensitive academic records, assessment results, password hashes, and authentication tokens were not exposed. Furthermore, the breached data did not contain links between user accounts and specific schools, which may mitigate some privacy risks.

Historical Background: The Rise of Educational Hacking

Educational technology (EdTech) has become a high-value target for cybercriminals. As schools transition to digital-first learning, the centralized storage of student data creates a single point of failure. Similar breaches in recent years have shown that hackers often use this information not for direct financial gain, but to fuel sophisticated phishing campaigns targeting minors and their families.

Did You Know?: SQL Injection is one of the oldest web vulnerabilities, yet it remains one of the most effective methods for large-scale database theft.

Frequently Asked Questions

1. Is my academic performance data safe?
Yes, Mathspace confirmed that academic records, learning activities, and assessment results were not part of the breach.

2. How can I protect myself from follow-up attacks?
Be extremely cautious of unsolicited emails or messages that reference your Mathspace account, as hackers may use the stolen info for phishing.