Mathspace Confirms Data Breach After Metabase Vulnerability Exploitation
Education platform Mathspace confirmed unauthorized access to its internal reporting system. The incident affects 1,079,819 people in Australia and New Zealand.

The Mathspace data breach affected 1,079,819 students, parents or legal guardians, school staff, and company employees. The education platform said attackers gained administrative access to its internal reporting system through a vulnerability in a self-hosted Metabase installation. Only people in Australia and New Zealand were affected.
According to the company, the unauthorized access began on August 10, 2026, and the data was downloaded on August 27. Mathspace confirmed the incident on September 3, disclosed it on September 5, and began sending individual notifications to affected people on September 6.
Mathspace data breach: What data may have been exported
Exported data may have included internal user identifiers, usernames, names, email addresses, country, time zone, user type, and information related to activity or account creation.
Mathspace also said that passwords or their hashes, SSO and authentication tokens, and API credentials were not exposed in the incident. According to the company, unaffected data also includes academic results, grades, and records of educational activities.
Even without login credentials, combinations of names, email addresses, account types, and information about a person’s relationship with the platform could make targeted phishing messages more convincing. Attackers could pose as Mathspace or a school, especially when contacting parents, students, or school staff.
Metabase vulnerability and actions taken
Metabase confirmed that the vulnerability affected installations running version 0.58 and later. The flaw enabled a chain attack that could result in the creation of an administrative session and bulk data downloads. Metabase released fixed versions on August 6, 2026.
Mathspace shut down the compromised Metabase installation, revoked its API keys, blocked the relevant database access, and changed the passwords for Metabase Cloud SQL databases. It also notified authorities in Australia and New Zealand.
The case is a specific confirmed exploitation of the Metabase vulnerability in a publicly accessible self-hosted installation. It also highlights the importance of processing and escalating vendor security alerts for systems that have access to internal reports and user databases.
Investigation continues; attacker not confirmed
The attacker’s identity has not yet been confirmed. Mathspace says its investigation has so far found no evidence that the stolen data was published, sold, distributed, or misused. However, this is a status reported by the company itself, not an independently verified conclusion.
BleepingComputer placed the incident within a broader wave of attacks against Metabase installations and mentioned a possible connection to the ShinyHunters group. Mathspace has not confirmed this attribution.
Further developments may include the results of Mathspace’s post-incident and forensic investigation, possible action by regulators in Australia and New Zealand, or evidence that the data was published or misused. It will also be important to determine whether additional victims of the campaign against vulnerable Metabase installations are confirmed.
Sources
- Mathspace – Data breach: what happened and what affected users should know – Primary confirmation of the scope of 1,079,819 affected people, exposed and unaffected data categories, the timeline, remediation steps, and notifications to authorities.
- Metabase – August 2026 Security Vulnerability: What happened? – Primary description of the vulnerability, its practical exploitation to obtain an administrative session, and the release of fixes on August 6, 2026.
- BleepingComputer – Mathspace discloses data breach affecting over 1 million people – Independent news confirmation of the incident’s disclosure and the broader context of attacks against Metabase instances; the ShinyHunters attribution remains unconfirmed.
Verified and updated: September 7, 2026 15:25



