Mathspace discloses breach exposing data of 1.08 million students and staff

This digest was compiled by AI from multiple sources — links to the originals are below.
Australian edtech Mathspace disclosed that attackers stole personal data of 1,079,819 students, staff, and parents after breaching its Metabase reporting system. The breach affected only users in Australia and New Zealand, with data downloaded on August 27. The company warned affected individuals to watch for suspicious account activity.
Key Facts
- Attackers exploited a vulnerability in Mathspace's self-hosted Metabase installation to gain administrator access without a legitimate login.
- The breach affected 1,079,819 people, comprising students, staff, and parents or guardians combined, only in Australia and New Zealand.
- Threat actors gained access to the compromised systems on August 10 and downloaded data from Mathspace's Australian reporting database on August 27.
- No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed.
- Mathspace CTO Alvin Savoy warned that attackers may target affected students and staff using the stolen data.
Breach Discovery
Mathspace confirmed on September 3, 2026, that unauthorised parties had accessed an internal reporting system and downloaded information on students, their parents or guardians, and school staff. The attackers exploited a security vulnerability in Mathspace's self-hosted installation of Metabase, software used for internal reporting. This vulnerability allowed the attackers to obtain administrator access to the system without a legitimate login. The threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27.
Data Exposure
A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected. No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools, but for schools with identifiable email domains, this may be possible.
Company Response
Mathspace CTO Alvin Savoy advised affected students and school staff to watch for suspicious account-related activity, such as changes to account details and password-reset messages. Savoy warned that attackers may target affected individuals using the stolen data. The breach adds to a string of incidents impacting Metabase instances of multiple companies worldwide over the last month.