Mathspace data breach leaks 1M+ student records
Mathspace, an online math learning platform used by thousands of schools, says attackers broke into its internal reporting system and stole personal data on more than 1 million students, parents, guardians, and staff. Only people in Australia and New Zealand had their information taken.
- Report priority
- Medium
- Victim
- Mathspace
What is known
Attackers exploited a security flaw in Mathspace's self hosted copy of Metabase, the reporting software the company uses internally, to get administrator access without a real login, then downloaded records from its Australian reporting database.
What to do
Mathspace has not published a self-service lookup tool, so watch for a direct notification from the company. There is no personal software to patch since this was a breach of Mathspace's own systems, so the practical step is to watch for password-reset emails or account-detail changes you did not request and report them.
If you run a self-hosted Metabase instance for internal reporting, make sure it is updated to a current release and not exposed with default or weak admin access, since Mathspace and several other companies were breached through a Metabase flaw that granted admin access without a login.
Reported details
Unknown attackers first got into Mathspace's systems on August 10, 2026 through a flaw in its Metabase reporting tool that let them log in as an administrator without real credentials. On August 27 they downloaded personal records from the Australian reporting database. Mathspace only confirmed the theft on September 3 and disclosed it publicly the following weekend. The stolen data covered students, parents and guardians, and school staff, but not passwords, academic records, or login tokens.
The breach traces to a vulnerability in a self-hosted Metabase deployment, the open source business intelligence tool Mathspace used for internal reporting. The flaw let attackers reach administrator-level access without valid credentials, reportedly tied to a broader SQL injection zero-day in Metabase that a group tracked as ShinyHunters has used against multiple companies' Metabase instances over the past month, including Trezor. Attackers accessed Mathspace's environment on August 10, 2026, and downloaded data from its Australian reporting database on August 27, 2026, ahead of an August confirmation and a public disclosure the following weekend. No passwords, password hashes, authentication tokens, SSO credentials, API credentials, or academic records were exposed.