Mathspace breach exposes data of 1 million people
Mathspace, an online math platform used by schools in Australia and New Zealand, says attackers broke into its internal reporting system and stole personal details on more than 1 million students, parents, and staff.
- Report priority
- High
- Involves
- Mathspace
What is known
- Attackers exploited a critical flaw in Mathspace's self-hosted copy of Metabase, an internal reporting and dashboard tool, gaining administrator access without a legitimate login.
- A critical security advisory for Metabase was issued on August 6, but Mathspace's process for tracking such warnings failed to flag it in time.
- The intruders got into the system on August 10 and stayed until they pulled data from Mathspace's Australian reporting database on August 27.
- Mathspace updated Metabase on August 29 after a later notice, but skipped the extra compromise checks recommended for potentially affected instances.
- A review of access logs, done after the September 3 discovery, confirmed the break-in had happened weeks before that update.
What to do
Mathspace says it began notifying school contacts on September 4 and emailing affected individuals directly starting September 6, so check your inbox, including spam, for a message from Mathspace. This exposure only covers Australian and New Zealand Mathspace accounts, so US and UK users are not part of it. The stolen data included your name, email address, internal user ID, country, and account activity dates, but not your password, academic work, or a direct record linking you to your school.
Watch for phishing, impersonation, or password-reset emails that reference your Mathspace account or your school, and never click links or share verification codes in unsolicited messages. Mathspace took the affected Metabase system offline, revoked its Metabase API keys, and changed related database credentials while it investigates. Report any suspicious Mathspace-themed messages to your school or to Mathspace. The breach has also been reported to Australia's OAIC and ACSC and New Zealand's privacy authorities, so watch for any official guidance from those agencies too.
Reported details
Attackers abused a critical flaw in Mathspace's self-hosted Metabase instance, a business-intelligence dashboard tool, to get administrator access without any valid login. A critical advisory for the underlying Metabase issue was published on August 6, but Mathspace's internal process for tracking vendor advisories failed to escalate it, leaving the instance exposed. Intruders got in on August 10 and pulled data from the Australian reporting database on August 27; Mathspace updated Metabase on August 29 but skipped the compromise checks Metabase recommended for potentially affected instances. Other Metabase-linked breaches around the same period, including at Trezor's shipping provider, Framework, and Tally, have been mentioned alongside the extortion group ShinyHunters, but attribution for the Mathspace incident specifically has not been confirmed.