Mathspace Breach Exposes 1M in Data Theft
Mathspace discloses a data breach affecting over 1 million students, staff, and parents after a Metabase vulnerability.
When Mathspace discovered on September 3 that unauthorized parties had accessed one of its internal systems, the company knew the damage was already extensive: data belonging to more than a million people had been downloaded. The breach, disclosed over the weekend, affects students, staff, and parents across Australia and New Zealand, adding to a growing wave of incidents tied to compromised Metabase installations.
Inside the Attack
According to Mathspace CTO Alvin Savoy, attackers exploited a security vulnerability in the company's self-hosted Metabase, a tool used for internal reporting. The flaw provided administrator access without a legitimate login, allowing the threat actors to navigate the system freely.
Although the data theft was confirmed on September 3, the attackers had already gained access on August 10 and exfiltrated data from Mathspace's Australian reporting database on August 27. The breach specifically targeted records of students and school staff from Australia and New Zealand, leaving other regions unaffected.
Scope of Exposed Data
The stolen data includes personal information of students, parents or guardians, and school staff. In total, 1,079,819 individuals were affected, combining these groups. Savoy noted that Mathspace staff records were also part of the exposure.
Despite the scale, the company emphasized that sensitive academic details were not compromised. Passwords, authentication tokens, SSO credentials, and API credentials remained secure. However, for schools with identifiable email domains, there is a risk that attackers could link some accounts to their respective institutions.
On 3 September 2026, we confirmed that unauthorised parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff. Mathspace staff records were also affected.
— Alvin Savoy, CTO at Mathspace
Warning to Affected Users
Savoy cautioned affected students and staff to remain vigilant against potential misuse of their stolen data. He advised monitoring for suspicious account activity, such as unexpected changes to account details or unsolicited password-reset messages, as attackers may attempt targeted phishing or account takeover attempts.
Part of a Larger Campaign
This breach is not isolated. Over the past month, multiple companies have reported incidents involving their Metabase instances. BleepingComputer has previously covered how attackers exploited a critical Metabase SQL injection zero-day vulnerability to gain administrator access and steal data.
Hardware wallet maker Trezor revealed on August 13 that nearly 14,000 customers were affected after a breach at its logistics provider, ShipMonk. By Friday, that number had climbed to 81,000. While Trezor has not named a specific attacker, BleepingComputer reported that ShipMonk received extortion emails from the ShinyHunters gang, which also added Metabase to its dark web leak site on August 11.
Other victims include laptop manufacturer Framework and form-building platform Tally, both of which experienced data breaches after their Metabase systems were compromised.
ShinyHunters' Track Record
The extortion group ShinyHunters has a history of high-profile breaches. According to BleepingComputer, the group has been linked to attacks on more than a dozen Snowflake customers, as well as Salesloft Drift and Salesforce Aura campaigns that targeted hundreds of Salesforce users. Additionally, they have been connected to over 100 enterprise victims following data-theft attacks exploiting an Oracle PeopleSoft zero-day flaw.
Why It Matters
The Mathspace incident underscores the risks that educational platforms face in handling vast amounts of personal data. With over a million individuals potentially at risk, the breach could lead to increased phishing and identity theft attempts against students and families. For schools using such platforms, this raises concerns about data security measures and the need for transparent communication in the aftermath of such incidents.
Sources
- BleepingComputer Original source
Continue Reading
North Korea's Linux Espionage Toolkit Deepens Threat
Rapid7 reports a new Linux toolkit from North Korean hackers targeting South Korean firms, enabling long-term espionage.
JSCeal Expands Beyond Stolen Google Sessions
A complex JavaScript-based malware that can replay stolen browser sessions to breach Google accounts keeps evolving, researchers warn.
MikroTik SSH Attacks Raise Router Security Stakes
Attackers exploit exposed SSH on MikroTik routers for full admin access; CERT Polska urges patching.