Mathspace Data Breach Exposes Over 1 Million Students, Teachers and Parents

Online mathematics platform Mathspace has disclosed a data breach affecting more than 1 million students, teachers, staff and parents or guardians, after hackers exploited a known vulnerability the company was slow to patch.

A Known Flaw, Patched Too Late

Mathspace says the breach traces back to its self-hosted Metabase analytics instance, which was compromised using CVE-2026-72898, a maximum-severity SQL injection vulnerability that Metabase had already patched on Aug. 6 after it was exploited in the wild as a zero-day. The extortion group ShinyHunters claimed responsibility for hacking Metabase shortly after that patch was released.

According to Mathspace’s incident notice, unauthorized access began on Aug. 10, and data was downloaded from its Australian reporting database on Aug. 27. The company did not escalate Metabase’s critical advisory internally and did not upgrade its instance until Aug. 29, more than two weeks after the patch became available, and it also failed to complete the compromise checks Metabase had recommended, which meant the intrusion went undetected when the update was finally applied.

What Was Exposed

The breach affects 1,079,819 students, teachers, staff and parents or guardians in Australia and New Zealand. Exposed data includes names, user IDs, usernames, email addresses, email verification status, time zone, country, date joined, and last login and account-active dates. Mathspace says no academic records, learning activity, assessment results, password hashes, authentication tokens or API credentials were exposed, and the leaked data does not link user accounts to specific schools.

Response and Warning to Users

Mathspace has taken the affected Metabase instance offline, revoked API keys, disabled the associated database accounts, reset passwords and exported logs for investigation. The company says it is reviewing why the original security advisory was not escalated and why recommended compromise checks were skipped, and is changing its internal processes as a result. Mathspace has reported the incident to Australian authorities and began notifying affected individuals over the weekend, warning that the stolen contact information could be used to craft convincing phishing messages referencing accurate details of the incident.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *