Skip to main content
cybersecurity

Mathspace Data Breach Exposes Information on 1.08 Million Users After Metabase Vulnerability

Mathspace says 1,079,819 people in Australia and New Zealand were affected after attackers exploited a vulnerability in its self-hosted Metabase reporting system. Names, emails and account details were exposed, while passwords and authentication credentials were not.

Xcademia Team

Xcademia Research Team

Sep 08, 20267 min read3 views
Share:
Mathspace Data Breach Exposes Information on 1.08 Million Users After Metabase Vulnerability

Online mathematics platform Mathspace has confirmed a data breach affecting 1,079,819 people in Australia and New Zealand, including students, parents or guardians, teachers, school staff and Mathspace employees.

The company said attackers gained unauthorised access to an internal reporting system and downloaded information from an Australian reporting database. The incident involved a vulnerability in a self-hosted installation of Metabase, software Mathspace uses for internal reporting.

Mathspace confirmed the breach on September 3, 2026, after investigating historical access logs. The company says the attacker remains unidentified and that it currently has no evidence that the stolen information has been published, distributed, sold or otherwise misused.


How the Mathspace breach happened

The incident began with a vulnerability in Mathspace's self-hosted Metabase installation.

According to Mathspace, Metabase published a critical security advisory and patched versions on August 6, 2026. However, Mathspace's existing vulnerability-notification process did not identify and escalate the advisory for action.

The company later updated its Metabase installation on August 29, after another Metabase notice came to its attention.

That update did not immediately reveal the earlier compromise.

Mathspace's investigation found that unauthorised access dated back to August 10, while information was confirmed to have been downloaded from the Australian reporting database on August 27. Historical log analysis subsequently confirmed that attackers had accessed the system before the update was applied.

The company also acknowledged that it did not complete additional compromise checks recommended for potentially affected systems when the update was initially applied.

Mathspace says it is now reviewing why the original security advisory was not escalated and why post-update compromise checks were not completed sooner.


What data was exposed?

The breach involved considerably more than names and email addresses.

Mathspace says the exported information could include:

  • User ID

  • Username

  • First name

  • Last name

  • Email address

  • Country

  • Time zone

  • User type

  • Email-verification status

  • Last-active date

  • Last-login date

  • Date joined

The affected records covered students, parents or guardians, teachers and Mathspace staff. Not every affected record contained every listed field.

Mathspace also clarified that its internal user IDs could include identifiers associated with student accounts.

Importantly, the company said the exposed dataset did not contain records directly linking user accounts to their schools. However, Mathspace acknowledged that identifiable school email domains could potentially make such associations possible.


What was not exposed?

Mathspace says several categories of sensitive information were not involved.

The company stated that the breach did not expose:

  • Academic records

  • Learning activities

  • Results

  • Assessment records

  • Passwords or password hashes

  • Authentication tokens

  • Single sign-on credentials

  • API credentials

Mathspace also says customer passwords and other authentication credentials were not exposed. As a result, it is not requiring users to reset their Mathspace passwords specifically because of this incident.

However, the company recommends changing passwords that were reused on other services.

info-1


Why the incident matters

The Mathspace breach highlights a familiar enterprise security challenge: a vulnerability does not necessarily become an incident at the moment it is disclosed.

The security process surrounding the vulnerability also matters.

In this case, Mathspace says its vulnerability-notification process failed to identify and escalate the initial Metabase advisory. The company subsequently updated the affected system after receiving a later notice, but the compromise had already occurred.

This illustrates the importance of connecting vulnerability management with incident detection and verification.

For enterprises, this could mean that patching alone is not enough when a vulnerable system may already have been accessed.

Organisations may also need processes that answer three separate questions:

  1. Was a vulnerability disclosed?

  2. Was the affected system patched?

  3. Was the system potentially compromised before the patch?

The third question becomes particularly important for internet-facing or privileged infrastructure.


1.08 million people affected

Mathspace says 1,079,819 people were affected.

The affected population was limited to Australia and New Zealand, according to the company's investigation. The group included students, parents or guardians, teachers and Mathspace staff.

The significance of the incident is not limited to the number of records.

The exposed information can provide attackers with useful context for impersonation and social engineering. A combination of a person's name, email address, account type and activity-related information can make a fraudulent message appear more credible.

Mathspace itself warns that attackers could potentially use the information to make messages appear to originate from Mathspace, a school or another familiar organisation.

info-2


What affected users should do

Mathspace says affected users should be cautious about unexpected communications.

The most important concern is potential phishing or impersonation.

Users should:

  • Treat unexpected emails and messages cautiously, even when they contain accurate personal information.

  • Verify communications independently using contact details obtained from an official website.

  • Never provide passwords or verification codes in response to unsolicited messages.

  • Avoid unexpected attachments and unfamiliar login links.

  • Use unique passwords across different services.

  • Change passwords that have been reused on other websites.

  • Watch for unexpected password-reset emails or changes to account information.

  • Report suspicious activity to Mathspace through its official breach-response channel.

Mathspace also notes that former or inactive users could potentially be affected if their information remained in the reporting database.

That means simply no longer using Mathspace does not establish that a person's information was outside the affected dataset.


Mathspace's response

After confirming the breach on September 3, Mathspace took the affected reporting environment offline.

The company says it:

  • Took Metabase offline

  • Revoked all Metabase API keys

  • Disabled Metabase database-access accounts in its Australian and US Snowflake environments

  • Changed passwords for the Metabase Cloud SQL databases

  • Preserved the Metabase application database and access logs for investigation

Mathspace says Metabase remains offline while recovery work continues, including reviewing unauthorised accounts and sessions and verifying the conditions required before the system can return to service.

The company began notifying school contacts on September 4 and said individual notifications began on September 6.

Mathspace has also notified the Office of the Australian Information Commissioner, the Australian Signals Directorate's Australian Cyber Security Centre, the New Zealand Office of the Privacy Commissioner and the New Zealand National Cyber Security Centre. Australian state and territory education departments were also notified.

info-3


The broader cybersecurity lesson

The Mathspace incident highlights a broader industry shift toward treating vulnerability management as a continuous security process rather than a simple patching exercise.

A critical vulnerability can create risk even when an organisation eventually installs the appropriate update. If attackers gained access before remediation, security teams also need to determine whether that access was used and whether data was extracted.

Mathspace's disclosure is particularly notable because the company has publicly identified weaknesses in its own vulnerability-notification and post-patch investigation processes.

For enterprises, this could mean strengthening the connection between security advisories, asset ownership, patch prioritisation, logging and compromise assessment.

The incident also demonstrates why internal reporting and analytics systems deserve the same security attention as customer-facing applications. A reporting platform may not be the primary product users interact with, but it can still have privileged access to valuable organisational data.


What happens next?

Mathspace says its remaining work includes completing individual notifications, responding to school requests and performing recovery checks before the reporting system can return to service.

The company also says its post-incident review will examine how critical security advisories are received and escalated and how potential compromise is checked after vulnerabilities are disclosed.

At present, Mathspace says the attacker remains unidentified and that it has found no evidence that the exposed information has been published, distributed, sold or otherwise misused.

For affected users, the immediate priority is therefore vigilance rather than panic. The exposed information can increase the credibility of phishing and impersonation attempts, even though the company says passwords and authentication credentials were not part of the breach.

Source: Mathspace

#Mathspace#DataBreach#Cybersecurity#EducationTechnology#Metabase#DataSecurity#Phishing#VulnerabilityManagement

About the Author

X
Xcademia Team
Xcademia Research Team
Share:
Learn to stop attacks like this oneCybersecurity Engineer Bootcamp: live cohorts enrolling now, with optional Career+ support.