AUTO-UPDATED

Mathspace breach exposes data on over a million students and parents

Mathspace has confirmed a data breach affecting over one million users in Australia and New Zealand after attackers exploited an unpatched vulnerability in its internal reporting software.

Key Points

  • Attackers accessed the Mathspace reporting system between August 10 and August 27, 2026, by exploiting a known vulnerability in a self-hosted Metabase instance.
  • The breach exposed the personal information of 1,079,819 students, parents, and school staff, including names, email addresses, and account activity timestamps.
  • Mathspace stated that no passwords, academic records, or authentication tokens were compromised during the unauthorized access.
  • The company has taken the affected reporting system offline and confirmed that no evidence currently suggests the stolen data has been sold or misused.
  • Similar Metabase-related security incidents were reported by companies including Framework, Tally, and Kilo Code throughout August 2026.

Why it Matters

This incident highlights the significant security risks associated with unpatched third-party business intelligence tools integrated into educational platforms. While sensitive academic records remain secure, the exposure of contact information increases the risk of targeted phishing attacks against students and their families.
Help Net Security Published by Sinisa Markovic
Read original