Mathspace breach exposes 1.08M users in Australia, New Zealand
Mathspace disclosed attackers exploited a Metabase SQL injection (CVE-2026-72898) and exposed personal data for 1,079,819 users in Australia and New Zealand.
Mathspace disclosed a data breach that exposed personal information for 1,079,819 students, teachers, staff and parents or guardians in Australia and New Zealand. Attackers exploited a critical SQL injection in the company’s self-hosted Metabase instance, tracked as CVE-2026-72898 with a CVSS score of 10.0.
Metabase published a patch for the vulnerability on August 6, 2026, after it was seen being exploited in the wild. Mathspace upgraded its Metabase instance on August 29, 2026, and did not complete the compromise checks Metabase had recommended when applying the update. An internal investigation found unauthorized access beginning on August 10, 2026, and confirmed that information was downloaded from the company’s Australian reporting database on August 27, 2026. The company says it discovered the incident in early September 2026.
The data the attackers downloaded includes names, user IDs, usernames, email addresses, email verification status, time zone, country, date joined, and last login and active dates. The company reported that no academic records, learning activities, results, assessment records, password hashes, authentication tokens, single sign-on credentials or API credentials were exposed. The compromised dataset did not include records linking user accounts to specific schools.
To contain the incident, Mathspace took its Metabase instance offline, revoked API keys, disabled the database access accounts involved, changed passwords and exported logs for forensic review. The company reported the incident to relevant Australian authorities and began notifying affected users over the weekend.
An extortion group identifying itself as ShinyHunters claimed responsibility for the attack shortly after Metabase published its advisory. The company did not provide details indicating whether the stolen data has been published or offered for sale.
“We are investigating why the initial advisory was not escalated and why those checks were not completed sooner. We are changing both processes as part of our incident response,” the incident notice said.
Mathspace warned the stolen contact and account information could be used to mount targeted phishing campaigns and urged potentially affected individuals to treat unsolicited messages referencing the incident with extreme caution. The company said it will continue its investigation and update users and authorities as further information becomes available.








