news.mlab.sh
Back to the feed
data-breach

Mathspace Data Breach Exposes Over 1 Million People

CriticalCVSS 10.0
Summary

Mathspace experienced a data breach affecting over 1 million students, teachers, and parents in Australia and New Zealand. Hackers exploited a vulnerability in their Metabase instance, gaining access to personal information like names, email addresses, and login details. The incident highlights a failure by Mathspace to prioritize patching and conduct thorough post-update checks, leading to a prolonged exposure of sensitive data.

Mathspace, an online mathematics program, has disclosed a data breach impacting over 1 million students, teachers, and parents in Australia and New Zealand. The incident began when hackers compromised Mathspace’s self-hosted Metabase instance using a known vulnerability – CVE-2026-72898 (CVSS score of 10/10), an SQL injection issue. The vulnerability was patched on August 6th, but the hackers exploited it as a zero-day for approximately three weeks before the fix was applied.

Shortly after the patches were released, the extortion group ShinyHunters claimed responsibility for the attack. Mathspace failed to escalate the critical advisory regarding Metabase, delaying patching and failing to complete recommended post-update checks. The initial unauthorized access dates back to August 10th, Australian Eastern Standard Time, and the hackers downloaded data including names, user IDs, usernames, email addresses, email verification status, time zone, country, date joined, and last login and active dates.

Mathspace has taken its Metabase instance offline, revoked API keys, disabled database access accounts, and changed passwords. The platform also exported logs for investigation. They have reported the incident to Australian authorities and begun notifying affected individuals.

Mathspace emphasized that no academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed, and that no data linked user accounts to their schools. However, the threat actors may now use the stolen information to launch phishing attacks, prompting affected individuals to exercise extreme caution with any unsolicited communications referencing the incident.

Read the full article at SecurityWeek