Mathspace Data Breach Exposes Information of Over One Million Users in Australia

The unauthorized access occurred between Aug. 10 and Aug. 27: attackers obtained administrator access on Aug. 10 and downloaded data on Aug. 27, before Mathspace confirmed the breach and took the system offline.
The incident involved a self-hosted installation of Metabase, an internal reporting tool; attackers exploited a known vulnerability after Mathspace had not installed the available security patch.
Mathspace said the exposed data did not directly include records linking user accounts to schools, although it acknowledged that school affiliation might be inferred for institutions using identifiable email domains.
Former Mathspace users may also have been affected because the reporting system contained account information beyond the currently active user base.
Mathspace advised recipients not to provide passwords or verification codes in response to messages and to independently verify purported contacts through an organisation’s official website rather than replying directly.
Mathspace, an online math platform serving schools across Australia and New Zealand, disclosed a data breach affecting 1,079,819 students, parents, guardians, and staff Cybersecurity News. Attackers exploited an unpatched security flaw in Metabase, an internal reporting tool, between August 10 and August 27 to access names, email addresses, usernames, user IDs, and account activity details Shattered.
The company confirmed the breach has taken the system offline and notified authorities and affected schools Streamline Feed. Mathspace said passwords, authentication tokens, academic records, and learning activities were not exposed, and it found no evidence the data was published or sold Newsy Today.
Hackers exploited a known vulnerability in Mathspace's self-hosted Metabase installation that the company had not patched HitechHub. On August 10, attackers obtained administrator access to the internal reporting tool. On August 27, they downloaded user data before Mathspace detected the breach and took the system offline Cybersecurity News.
The exposed data included names, email addresses, usernames, user IDs, and account-activity details, though not every affected person had all fields exposed Streamline Feed. Mathspace stressed that passwords, authentication tokens, single sign-on credentials, API credentials, and academic records remained secure. Former users may also have been affected because the reporting system contained account information beyond the current user base Cybersecurity News.
While the exposed data did not directly include records linking user accounts to schools, Mathspace acknowledged that school affiliation might be inferred for institutions using identifiable email domains Newsy Today. This means attackers could potentially identify which school a student or staff member attended based on their email address alone, adding another layer of risk to the exposure.
Officials are warning those affected to watch for phishing and impersonation attempts using the exposed information Shattered. Mathspace advised recipients not to provide passwords or verification codes in response to messages. People should independently verify purported contacts through an organisation's official website rather than replying directly to suspicious messages Streamline Feed.
Publishers
15
Articles
16
Reach
31