Mathspace Breach Exposes Data of Over 1 Million Students and Staff Amidst Wider Metabase Exploits
The online learning platform **Mathspace** has disclosed a significant data breach, affecting over 1 million students, staff, and parents primarily in Australia and New Zealand. Attackers exploited a critical vulnerability in the company's **Metabase** internal reporting system, gaining administrator access and exfiltrating personal information. This incident is part of a broader series of attacks targeting **Metabase** instances, with the notorious hacking group **ShinyHunters** linked to similar recent breaches.
Online maths learning platform **Mathspace** has revealed that attackers successfully breached its **Metabase** internal reporting system, compromising the data of more than 1 million students, staff, and parents.
Founded in Sydney in 2010, **Mathspace** serves thousands of schools across Australia, New Zealand, the United States, and the United Kingdom.
**Mathspace** CTO **Alvin Savoy** confirmed the incident in a Saturday blog post, stating that unauthorized parties accessed company systems and stole personal information.
"On 3 September 2026, we confirmed that unauthorised parties had accessed an internal reporting system used by **Mathspace** and downloaded information on students, their parents or guardians, and school staff. **Mathspace** staff records were also affected," **Savoy** detailed.
Attackers exploited a security vulnerability within **Mathspace**'s self-hosted **Metabase** installation, which is used for internal reporting. This vulnerability allowed them to obtain administrator access without legitimate login credentials.
While the data theft was confirmed on September 3, the initial access occurred on August 10, with data exfiltration from **Mathspace**'s Australian reporting database on August 27.
**Savoy** noted that only students and school staff from Australia and New Zealand were impacted. While no credentials, academic records, or learning activities were stolen, the attackers may have been able to link some affected accounts to their respective schools.
"A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected," **Savoy** added.
He further clarified, "No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools. However, for schools with identifiable email domains, we understand this may be possible."
**Savoy** warned affected individuals to be vigilant for suspicious account activity, such as unauthorized changes to account details or password-reset messages, as attackers may leverage the stolen data for targeted attacks.
## Metabase Breaches Claimed by ShinyHunters
This incident is not isolated, adding to a series of breaches impacting **Metabase** instances across various companies globally over the past month.
Threat actors have been exploiting a critical **Metabase SQL injection zero-day vulnerability** to breach customer instances, gaining administrator access and stealing data.
Hardware wallet manufacturer **Trezor** initially disclosed on August 13 that attackers stole data from nearly 14,000 customers by compromising its shipping and logistics provider, **ShipMonk**. This number has since escalated to 81,000 affected customers.
While **Trezor** has not publicly attributed the attack, **ShipMonk** reportedly received extortion emails from the **ShinyHunters** extortion gang. **ShinyHunters** also posted details to its dark web leak site on August 11, claiming responsibility.
The list of companies affected in this campaign also includes laptop maker **Framework** and online form-building platform **Tally**, both of whom have disclosed data breaches after their **Metabase** instances were hijacked.
**ShinyHunters** has a history of high-profile breaches, including those affecting over a dozen **Snowflake** customers, **Salesloft Drift**, and **Salesforce Aura** campaigns targeting hundreds of **Salesforce** customers. The group was also linked to attacks on over 100 enterprise victims following data-theft attacks exploiting an **Oracle PeopleSoft zero-day flaw**.

## Once attackers have valid credentials, only 37% of their actions are blocked
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
[Get the report](https://hubs.li/Q04sB3fb0)