Over 1 Million People’s Data Stolen in Mathspace Breach, with Attackers Linked to ShinyHunters Extortion Gang
Mathspace, a popular online maths learning platform used by thousands of schools across Australia, New Zealand, and other countries, has disclosed a massive data breach that exposed the personal information of over 1 million students, staff, and parents. The breach occurred when attackers exploited a vulnerability in Mathspace’s self-hosted installation of Metabase, software used for internal reporting.
According to Mathspace CTO Alvin Savoy, the attackers gained access to the company’s systems on August 10 and downloaded the data from the Australian reporting database on August 27. However, it wasn’t until September 3 that the breach was confirmed. The stolen data includes personal information of students, staff, and parents or guardians, but does not include academic records, learning activities, results, assessment records, passwords, authentication tokens, SSO credentials, or API credentials.
The breach adds to a string of other incidents impacting companies worldwide that use Metabase. In recent weeks, multiple companies have disclosed data breaches after their Metabase instances were hijacked by attackers. ShinyHunters, an extortion gang known for targeting Salesforce customers and exploiting Oracle PeopleSoft zero-day flaws, has been linked to several of these breaches.
Mathspace’s own investigation found that the vulnerability was exploited through a self-hosted installation of Metabase, which allowed attackers to obtain administrator access without a legitimate login. While the company did not provide details on how the breach occurred, it warned affected students and school staff that attackers may target them using the stolen data. As such, they are advised to watch for suspicious account-related activity, such as changes to account details and password-reset messages.
The Mathspace breach highlights the importance of securing internal reporting systems and software used by companies to manage sensitive information. Metabase is a popular choice among businesses due to its ease of use and flexibility, but it appears that some users may not be adequately protecting themselves against potential vulnerabilities.
In light of this incident, we urge all users of online platforms to exercise caution when dealing with data breaches. If you are an affected individual, keep a close eye on your account activity and be prepared for potential phishing attempts or other malicious activities. Companies must also prioritize the security of their internal systems and software to prevent such incidents from occurring in the future.
As a user of online services, it’s essential to stay informed about data breaches and take proactive steps to protect yourself against potential threats. By doing so, you can reduce your risk of becoming a victim of identity theft or other malicious activities.
Source: Bleeping Computer — 2026-09-07