← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

Mathspace discloses data breach affecting over 1 million students, staff, and parents

🔄 Updated 24d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Mathspace reported a data breach affecting 1,079,819 people.
  • Data stolen includes information on students, parents, and school staff.
  • Attackers exploited a vulnerability in Mathspace's Metabase system.
  • Only individuals in Australia and New Zealand were affected.
  • The vulnerability exploited was CVE-2026-72898, an SQL injection issue.
  • The vulnerability had a CVSS score of 10/10.
  • The vulnerability was patched on August 6, 2026.
  • ShinyHunters claimed responsibility for hacking Metabase.
  • Mathspace upgraded its instance on August 29, 2026.
  • Unauthorized access dated back to August 10, 2026.
  • Information was downloaded from the database on August 27, 2026.

Data Breach Details

Mathspace, an online maths learning platform, disclosed a data breach that affected over 1 million students, staff, and parents. The incident occurred when attackers breached the company's Metabase internal reporting system. The data theft was confirmed on September 3, 2026, though attackers gained access on August 10 and downloaded data on August 27.

Affected Individuals and Data

A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians from Australia and New Zealand. No academic records, learning activities, results, assessment records, passwords, authentication tokens, SSO credentials, or API credentials were exposed. While user accounts were not directly linked to schools in the exposed data, for schools with identifiable email domains, this link might be possible.

Vulnerability Exploited

Mathspace CTO Alvin Savoy stated that attackers exploited a security vulnerability in their self-hosted installation of Metabase. This vulnerability allowed unauthorized parties to obtain administrator access to the system without legitimate login credentials. Mathspace uses Metabase for internal reporting.

Impact and Recommendations

The stolen data primarily affects individuals in Australia and New Zealand. Mathspace has warned affected students and school staff that they may be targeted using the stolen information. The company advised vigilance for suspicious account activity, such as changes to account details and password-reset messages.

Updates

🕒 2026-09-08 · new reporting from SecurityWeek
  • The vulnerability exploited was CVE-2026-72898, an SQL injection issue.
  • The vulnerability had a CVSS score of 10/10.
  • The vulnerability was patched on August 6, 2026.
  • ShinyHunters claimed responsibility for hacking Metabase.
  • Mathspace upgraded its instance on August 29, 2026.
  • Unauthorized access dated back to August 10, 2026.
  • Information was downloaded from the database on August 27, 2026.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Mathspace, an online mathematics program, experienced a data breach affecting over 1 million individuals after hackers exploited a known Metabase vulnerability (CVE-2026-72898) that Mathspace failed to patch promptly. The incident exposed names, user IDs, email addresses, and other non-academic data, highlighting the risks of delayed patching of critical vulnerabilities.

Online learning platform Mathspace reported a data breach impacting over 1 million individuals in Australia and New Zealand. Attackers exploited a vulnerability in the company's self-hosted Metabase internal reporting system to steal personal information.