Mathspace discloses data breach affecting over 1 million people

Over a million people’s personal information exposed in Mathspace data breach

A devastating data breach has been disclosed by online maths learning platform Mathspace, affecting over 1 million students, staff, and parents across Australia, New Zealand, the United States, and the UK. The attackers exploited a vulnerability in Metabase, an internal reporting system used by the company, to gain administrator access and steal sensitive information.

Mathspace’s Chief Technology Officer Alvin Savoy revealed that unknown threat actors accessed the company’s systems on August 10 and downloaded data from its Australian reporting database on August 27. Although academic records and passwords were not stolen, the attackers may have been able to link some impacted accounts to their schools. A total of 1,079,819 people are affected, with only those in Australia and New Zealand targeted.

The breach is just the latest in a string of incidents impacting companies that use Metabase. ShinyHunters, an extortion gang linked to several high-profile breaches, has claimed responsibility for multiple attacks on Metabase instances over the past month. Companies like Trezor, Framework, and Tally have all disclosed data breaches after their Metabase instances were hijacked.

The implications of this breach are significant. With such a large number of people affected, there is a heightened risk of targeted attacks against individuals whose data has been stolen. Savoy warned that attackers may use the stolen information to target students and school staff with phishing scams or other types of cybercrime. He advised those affected to watch for suspicious account-related activity, including changes to account details and password-reset messages.

The vulnerability in Metabase was a zero-day flaw that allowed attackers to gain administrator access without legitimate login credentials. This highlights the importance of regular security updates and patches to prevent such attacks. Companies must prioritize cybersecurity and invest in robust protection measures to safeguard sensitive information.

For individuals affected by this breach, it’s essential to remain vigilant and take proactive steps to protect themselves from potential cyber threats. This includes monitoring account activity closely, using strong passwords, and being cautious of unsolicited emails or messages that may ask for personal information. By staying informed and taking necessary precautions, we can mitigate the impact of such breaches and prevent further exploitation.

As the cybersecurity landscape continues to evolve, it’s crucial for companies and individuals alike to prioritize security awareness and take proactive measures to protect against data breaches. This incident serves as a stark reminder of the importance of robust cybersecurity defenses in preventing such attacks from happening in the first place.


Source: Bleeping Computer — 2026-09-07