Mathspace confirms data breach affecting more than 1 million users
Mathspace didn’t calculate for this to happen.

Mathspace logo. Image by Cybernews
- Mathspace confirmed a data breach affecting 1,079,819 students, staff, and parents in Australia and New Zealand.
- Attackers used a Metabase security flaw to gain administrator access and download user data.
- Exposed data included names, emails, usernames, user IDs, countries, time zones, and login dates.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Online mathematics program Mathspace has been breached, affecting over 1 million people in Australia and New Zealand.
According to a press release published last weekend, attackers exploited a security vulnerability in Metabase, the company's self-hosted software for internal reporting.
The vulnerability allowed the attackers to obtain administrator access to Metabase without a legitimate login.
A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected.
The exfiltrated information included first and last names, usernames, user IDs, email addresses, countries, time zones, user types, email-verification status, last-active dates, last-login dates, and dates joined.
“No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, single sign-on (SSO) credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools. However, for schools with identifiable email domains, we understand this may be possible,” chief technology officer (CTO) Alvin Savory said in a press release.
The data breach was confirmed on September 3rd, 2026. However, the hackers compromised Mathspace’s system on August 10th and downloaded the data on August 27th.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
As soon as the incident came to light, Mathspace took Metabase offline, revoked all Metabase API keys, disabled Metabase’s database access accounts in their Australian and US Snowflake environments, and changed the passwords for the Metabase Cloud SQL databases.
The Office of the Australian Information Commissioner (OAIC), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), New Zealand’s Office of the Privacy Commissioner, and New Zealand’s National Cyber Security Centre (NCSC) have been notified of the incident.
Affected individuals should be vigilant about phishing attempts. They are advised to check unexpected messages independently, not disclose passwords or verification codes, change their password to a unique one, monitor for unusual account activity, and report any suspicious messages or activity to Matchspace.
Mathspace hasn’t attributed the incident to any specific threat actor. But according to cybersecurity analyst Dominic Alvieri, ShinyHunters added Metabase to its dark web leak site on August 11th.