Mathspace breach exposes 1M+ Aussie/NZ user emails

Published September 3, 2026

Mathspace, a math learning platform used in schools, had an internal reporting system broken into. Attackers downloaded names, emails, and account details for more than a million students, parents, teachers, and staff in Australia and New Zealand.

Report priority
High
Targets
Metabase

How it works

Mathspace ran its own copy of Metabase, a data reporting tool, for internal use, and a flaw in that installation let an outsider log in as an administrator without a real password, then pull data out of it.

What to do

Watch for phishing or scam emails that use your real name or Mathspace account details to look convincing, since names and emails were exposed even though passwords were not. If you receive a notification from Mathspace about this breach, follow the specific instructions it gives rather than generic advice.

Technical details

Affected software: Metabase

Mathspace runs a self-hosted copy of Metabase, a business intelligence tool, to power its internal reporting. Metabase discloses a critical flaw that lets an attacker gain administrator access without logging in, and ships a fix on August 6, 2026. Mathspace's own process fails to flag that advisory, so the vulnerable installation stays exposed. An unauthorized party uses the flaw to reach the reporting system and downloads records on students, parents, teachers, and staff before Mathspace updates the software on August 29, 2026.

The exposure traces back to a self-hosted Metabase instance Mathspace used for internal reporting. Metabase, an open-source business intelligence tool, published a critical advisory in early August 2026 for a flaw that let an attacker obtain administrator access without a valid login, and released a patched version on August 6. Mathspace's internal process for tracking vendor security advisories did not flag or escalate that notice, so the vulnerable instance remained reachable until Mathspace updated it on August 29, after noticing unusual activity. In that window, unauthorized parties accessed the reporting system and downloaded records covering 1,079,819 people, including names, email addresses, and account details, but not passwords or SSO tokens.