Mathspace breach exposes personal data of over a million students and staff

Mathspace, an online math learning platform, confirmed that attackers accessed its internal Metabase reporting system and stole personal information of more than 1 million users in Australia and New Zealand. The breach occurred between August 10 and September 3, 2026, and involved exploitation of a vulnerability that granted administrator access. The company warns affected individuals to be vigilant against phishing and account-related suspicious activity.
The intrusion window spanned from August 10 to September 3, with attackers downloading the Australian reporting database on August 27. The exploit targeted a critical SQL injection flaw in Mathspace's self-hosted Metabase tool, granting unauthorized administrator access without valid login credentials.
Stolen records included personal details for 1,079,819 individuals, though no academic results, passwords, or authentication tokens were taken. The incident aligns with a broader campaign by the cybercriminal group ShinyHunters, which has recently compromised Metabase instances at Trezor, Framework, and Tally, among others.
This breach could expose a large cohort of minors and educators to targeted phishing and social engineering attacks, as stolen personal details may be used to craft convincing lures. Affected families may face heightened risks of identity fraud or credential-stuffing attempts. While no academic records were taken, the loss of personal data could erode trust in educational technology platforms, prompting schools and parents to demand stricter security audits for third-party vendors.