Mathspace Data Breach Affects 1.08 Million Students, Parents and Staff

Mathspace Data Breach Affects 1.08 Million Students, Parents and Staff

Mathspace says hackers exploited a Metabase flaw and downloaded account data belonging to 1.08 million students, parents and staff in Australia and New Zealand.

Listen to this article

0:00

Press play to start listening

Mathspace has disclosed a data breach affecting 1,079,819 students, parents, guardians, teachers and company employees in Australia and New Zealand after hackers downloaded information from an internal reporting database.

The education platform confirmed the breach on September 3, nearly four weeks after the attackers first gained unauthorized access. Its investigation found activity dating to August 10 and determined that information was downloaded from its Australian reporting database on August 27.

Hackers Exploited an Unpatched Metabase Flaw

Attackers entered through Mathspace’s self-hosted installation of Metabase, business intelligence software used to examine database information and generate reports. According to Mathspace, the vulnerability allowed them to obtain administrator access without a valid login.

Tracked as CVE-2026-72898, the weakness is a critical SQL injection vulnerability in Metabase’s password-reset endpoint. Metabase disclosed and patched the flaw on August 6 after detecting attacks against its cloud service.

According to the official security advisory, an unauthenticated attacker could manipulate the Metabase application database, obtain administrator privileges, steal credentials for connected databases, and export accessible information. The vulnerability received a CVSS score of 10.0.

Mathspace did not install the update until August 29, after receiving a later notice from Metabase. The company said its vulnerability-notification process had failed to identify and escalate the original critical advisory. It also acknowledged that staff did not complete the checks Metabase recommended for detecting earlier unauthorized access when the update was installed.

A subsequent review of historical logs revealed that the system had already been compromised. The US Cybersecurity and Infrastructure Security Agency (CISA) had added CVE-2026-72898 to its Known Exploited Vulnerabilities catalog on August 11.

Names and Account Details Downloaded

Information taken from the database included names, usernames, email addresses, internal user IDs, countries, time zones, account types, email-verification status, account creation dates, and recent login or activity dates. Mathspace noted that not every field was present for every person.

Mathspace said the stolen information did not include passwords or password hashes, authentication tokens, single sign-on credentials, API credentials, academic records, assessment results or learning activities. The exported records did not directly connect accounts to individual schools, although an identifiable school email domain may reveal that association.

However, even without passwords, the exposed information could help criminals prepare convincing phishing messages that impersonate Mathspace, schools or education officials. Recipients should be cautious of emails that mention accurate personal or account information while asking them to follow a link or provide credentials.

So far, the company has found no evidence that the information has been published, sold, or otherwise misused. It has not identified the attackers or attributed the breach to a known group.

Mathspace Takes Reporting System Offline

After confirming the breach, Mathspace took the affected Metabase system offline, revoked its API keys, disabled associated database accounts, and changed relevant passwords. The company also preserved application data and access logs for its investigation.

Mathspace reported the incident to privacy and cybersecurity authorities in Australia and New Zealand on September 4. Schools were contacted first, followed by notifications to affected individuals beginning September 6.

Customers can continue using Mathspace, and the company is not requiring password resets because login credentials were not exposed. Anyone receiving a message about the breach should verify it through Mathspace’s official website or by contacting the company through independently obtained details.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts