
Mathspace Data Breach Hits Over 1 Million Students and Parents
.webp)
Mathspace has confirmed a data breach affecting 1,079,819 students, parents, guardians and school staff across Australia and New Zealand. Attackers exploited a critical flaw in the company's self-hosted installation of Metabase, the software it uses for internal reporting, and downloaded records from its Australian reporting database. The Sydney-based maths learning platform serves thousands of schools in Australia, New Zealand, the United States and the United Kingdom. Only users in Australia and New Zealand fall inside the confirmed scope of the Mathspace data breach.
The company confirmed the theft on 3 September and published a public account of it two days later. It began notifying school contacts on 4 September and started writing to individuals on 6 September. Investigators have found no evidence so far that the stolen data has been published, sold or otherwise misused. The identity of the attacker remains unknown.
What the Attackers Took
The exported records included user ID, username, first name, last name and email address. They also carried country, time zone, user type, email verification status, last active date, last login date and date joined. Not every field appeared for every person. The user IDs are internal Mathspace identifiers, and some of them belong to student accounts.
Mathspace first described the exposure as names and email addresses alone, then corrected that account. Academic records, learning activities, results and assessment records stayed out of reach. The attackers also failed to reach passwords, password hashes, authentication tokens, SSO credentials and API credentials, so the company is not forcing a password reset.
One caveat matters for schools. The stolen records do not link user accounts to specific schools. But where a school uses an identifiable email domain, someone can still infer that connection from the data.
How the Mathspace Data Breach Happened
Metabase published a critical advisory and patched versions on 6 August. The flaw lets an unauthenticated attacker inject SQL through the password reset endpoint and take administrator control of the application database. It carries a maximum severity score of 10.0, and CISA added it to the Known Exploited Vulnerabilities catalogue on 11 August.
Mathspace's vulnerability notification process did not pickup that advisory or escalate it for action. The company updated its instance on 29 August, after a later notice from Metabase came to its attention. By then attackers had held access since 10 August and had already pulled the data on 27 August.
A second failure compounded the first. When Mathspace applied the update, it skipped the additional compromise checks that Metabase recommended for potentially affected systems. Only a review of historical access logs on 3 September revealed that intruders had been inside before the patch landed. The company says it is now rebuilding both processes.
How Mathspace Contained the Incident
After confirming the breach, the company took Metabase offline and revoked all of its API keys. It disabled the Metabase database access accounts in its Australian and US Snowflake environments and changed thepasswords for the Metabase Cloud SQL databases. Engineers copied the application database and exported access logs for the investigation.
That last set of actions explains why an internal reporting tool carries so much weight. Metabase held live credentials for connected data stores across two regions. A system that never faces a customer became the route to more than a million records.
Mathspace reported the incident to the Office of the Australian Information Commissioner and the Australian Signals Directorate's Australian Cyber Security Centre on 4 September. It also notified New Zealand's Office of the Privacy Commissioner and National Cyber Security Centre, along with Australian state and territory education departments. Metabase remains offline while recovery checks continue.
Part of a Wider Metabase Campaign
The Mathspace data breach is the largest known incident tied to this flaw so far. Laptop maker Framework and form-building platform Tally have both disclosed data theft after attackers hijacked their Metabase instances. Automation platform n8n reported 136 affected customer records, five of which contained hashed passwords. Kilo Code confirmed the exposure of Slack access tokens belonging to a small subset of its users.
The extortion group ShinyHunters added a Metabase listing to its dark web leak site on 11 August. That group has been linked to data theft campaigns against Salesforce customers, Snowflake customers and more than 100 organisations running Oracle PeopleSoft. Mathspace has not attributed its own incident to any group, and no attacker has publicly claimed it.
What Affected Families and Schools Should Do
Names, email addresses and account details make impersonation far more convincing. Someone holding this data can send a message that appears to come from Mathspace, a school or another familiar organisation. Treat any unexpected message about the Mathspace data breach with suspicion, even one that uses your name correctly or refers accurately to your school.
Verify through channels you find yourself rather than links inside the message. Never share passwords or verification codes in reply to an email. Anyone who reused their Mathspace password on another service should change it there now. Watch for unexpected password reset emails and changes to account details.
Former users need to check as well. An account does not have to be active for its record to sit inside a reporting database. Leaving a school or dropping the platform does not put anyone outside the scope on its own. School administrators can request the affected numbers and records for their own community directly from Mathspace.
The Real Cost of a Missed Advisory
Twenty-three days separated the Metabase advisory from the patch at Mathspace, and another five separated the patch from detection. Neither gap came from a shortage of information. The fix existed on 6 August, and the guidance on checking for compromise sat alongside it.
For any organisation running self-hosted tooling, the practical lesson in the Mathspace data breach sits in the escalation path rather than the patch itself. Advisories only help when someone reads them and acts on them. Post-patch compromise checks carry equal weight, because a fix applied three weeks late closes the door on an attacker who may already be standing inside.
Subscribe to receive the latest blog posts to your inbox every week.