Mathspace breach exposes 1M+ Aussie/NZ user emails
Mathspace, a math learning platform used in schools, had an internal reporting system broken into. Attackers downloaded names, emails, and account details for more than a million students, parents, teachers, and staff in Australia and New Zealand.
- Report priority
- High
- Targets
- Metabase
How it works
Mathspace ran its own copy of Metabase, a data reporting tool, for internal use, and a flaw in that installation let an outsider log in as an administrator without a real password, then pull data out of it.
What to do
Watch for phishing or scam emails that use your real name or Mathspace account details to look convincing, since names and emails were exposed even though passwords were not. If you receive a notification from Mathspace about this breach, follow the specific instructions it gives rather than generic advice.
Technical details
Affected software: Metabase
Mathspace runs a self-hosted copy of Metabase, a business intelligence tool, to power its internal reporting. Metabase discloses a critical flaw that lets an attacker gain administrator access without logging in, and ships a fix on August 6, 2026. Mathspace's own process fails to flag that advisory, so the vulnerable installation stays exposed. An unauthorized party uses the flaw to reach the reporting system and downloads records on students, parents, teachers, and staff before Mathspace updates the software on August 29, 2026.
The exposure traces back to a self-hosted Metabase instance Mathspace used for internal reporting. Metabase, an open-source business intelligence tool, published a critical advisory in early August 2026 for a flaw that let an attacker obtain administrator access without a valid login, and released a patched version on August 6. Mathspace's internal process for tracking vendor security advisories did not flag or escalate that notice, so the vulnerable instance remained reachable until Mathspace updated it on August 29, after noticing unusual activity. In that window, unauthorized parties accessed the reporting system and downloaded records covering 1,079,819 people, including names, email addresses, and account details, but not passwords or SSO tokens.
References
- blog.mathspace.co · mathspace-data-breach-what-happened-and-what-affected-users-should-know The Cyber Express
- cyble.com · what-is-phishing The Cyber Express
- bleepingcomputer.com · idscan-sued-over-alleged-data-breach-affecting-153-million-drivers BleepingComputer
- infosecurity-magazine.com · fbi-probes-breach-153-million Infosecurity Magazine
- openwall.com · 7 Openwall oss-security