Mathspace Breach Exposes Data of 1.08 Million Students and Staff
A critical vulnerability in a reporting tool allowed unauthorized access to personal details of users across Australia and New Zealand.
Online mathematics learning platform Mathspace has suffered a massive data breach affecting 1,079,819 users across Australia and New Zealand. The incident exposes the personal information of students, parents, teachers, and staff, highlighting a significant security failure in the platform's reporting infrastructure.
Attackers gained entry by exploiting a critical vulnerability in a self-hosted Metabase reporting instance, which allowed them to obtain administrator privileges without requiring any credentials. The unauthorized access took place between August 10 and August 27, 2026, culminating in the bulk download of user data on August 27.
The Scope of Stolen Data
The compromised dataset includes a wide array of personal identifiers and account metadata. Confirmed stolen information consists of user IDs, usernames, first and last names, and email addresses. Additionally, the attackers accessed country and time zone data, user types, email-verification statuses, and account activity logs, including the dates users joined and their last login and activity timestamps.
Industry Implications
This breach is particularly concerning due to the nature of the affected population. The combination of full names and school-affiliated email domains creates a high-risk environment for targeted social engineering. Because the data links specific individuals to educational institutions, it provides a roadmap for attackers to launch convincing phishing campaigns.
Mathspace acknowledged the severity of the leak, stating that "names, email addresses and account details can make impersonation attempts more convincing." For school communities, this means an increased likelihood of fraudulent communications that appear to come from trusted educational sources, potentially leading to further credential theft or financial scams targeting parents and staff.
Next Steps and Outlook
While the technical entry point has been identified as the Metabase instance, the incident underscores the ongoing risk associated with self-hosted third-party reporting tools in educational technology. Users are advised to remain vigilant against unsolicited emails and to implement multi-factor authentication where possible to mitigate the risk of impersonation attacks.
It remains to be seen if further forensic audits will reveal whether the stolen metadata was used to pivot into other systems or if the breach was limited strictly to the reporting instance. For now, the focus remains on notifying the million-plus affected individuals and securing the remaining infrastructure against similar credential-less exploits.