Mathspace has confirmed a data breach affecting over one million users in Australia and New Zealand after attackers exploited an unpatched vulnerability in its internal reporting software.
Key Points
- Attackers accessed the Mathspace reporting system between August 10 and August 27, 2026, by exploiting a known vulnerability in a self-hosted Metabase instance.
- The breach exposed the personal information of 1,079,819 students, parents, and school staff, including names, email addresses, and account activity timestamps.
- Mathspace stated that no passwords, academic records, or authentication tokens were compromised during the unauthorized access.
- The company has taken the affected reporting system offline and confirmed that no evidence currently suggests the stolen data has been sold or misused.
- Similar Metabase-related security incidents were reported by companies including Framework, Tally, and Kilo Code throughout August 2026.