Mathspace, an online maths learning platform, disclosed a data breach that affected over 1 million students, staff, and parents. The incident occurred when attackers breached the company's Metabase internal reporting system. The data theft was confirmed on September 3, 2026, though attackers gained access on August 10 and downloaded data on August 27.
A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians from Australia and New Zealand. No academic records, learning activities, results, assessment records, passwords, authentication tokens, SSO credentials, or API credentials were exposed. While user accounts were not directly linked to schools in the exposed data, for schools with identifiable email domains, this link might be possible.
Mathspace CTO Alvin Savoy stated that attackers exploited a security vulnerability in their self-hosted installation of Metabase. This vulnerability allowed unauthorized parties to obtain administrator access to the system without legitimate login credentials. Mathspace uses Metabase for internal reporting.
The stolen data primarily affects individuals in Australia and New Zealand. Mathspace has warned affected students and school staff that they may be targeted using the stolen information. The company advised vigilance for suspicious account activity, such as changes to account details and password-reset messages.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Online learning platform Mathspace reported a data breach impacting over 1 million individuals in Australia and New Zealand. Attackers exploited a vulnerability in the company's self-hosted Metabase internal reporting system to steal personal information.