Mathspace data breach affects over 1 million
An online mathematics learning platform, Mathspace, has disclosed a significant data breach that exposed the personal information of over 1 million students, staff, and parents across Australia and New Zealand. The breach occurred after unauthorized parties exploited a critical vulnerability in the company's self-hosted Metabase business intelligence software. Attackers gained access to Mathspace's systems on August 10, 2026, and downloaded user data on August 27, 2026. The company confirmed the security incident on September 3, 2026. The vulnerability allowed attackers to obtain administrator access to the Metabase system without requiring credentials. The incident stemmed from a failure to promptly patch the Metabase installation. Metabase issued a critical security advisory and released patched versions on August 6, 2026. Mathspace acknowledged that its internal vulnerability notification process did not identify and escalate this advisory. The company eventually updated its Metabase instance on August 29, 2026, after becoming aware of the issue through a subsequent notice.