Online mathematics learning platform Mathspace has disclosed a data breach affecting 1,079,819 people in Australia and New Zealand, including students, parents or guardians, teachers, and company employees.

 

 

The intrusion involved Mathspace’s self-hosted installation of Metabase, an analytics platform used internally for reporting. Attackers exploited a security vulnerability that allowed them to obtain administrator-level access without having legitimate login credentials.

Mathspace traced unauthorized activity back to August 10th, 2026. Information was downloaded from its Australian reporting database on August 27th, but the company did not confirm that its environment had been compromised until September 3rd.

The vulnerability had already been addressed by Metabase before the intrusion was discovered. A critical security advisory and patched versions became available on August 6th. However, Mathspace said its vulnerability notification process failed to identify and escalate the advisory for action.

The company eventually updated its Metabase installation on August 29th after receiving a later notice. During a subsequent examination of historical access logs, investigators found evidence showing that unauthorized access had occurred before the update.

The information exported by the attackers varied between accounts. It could include internal user IDs, usernames, first and last names, email addresses, countries, time zones, user types, email verification status, dates of last activity and login, and account creation dates.

Importantly, Mathspace said passwords, password hashes, authentication tokens, single sign-on credentials and API credentials were not exposed. Academic information was also unaffected, including learning activities, results and assessment records. The stolen database did not contain records directly connecting individual accounts with their schools.

After confirming the breach, Mathspace took the compromised Metabase system offline and revoked its API keys. Database access accounts associated with the platform were disabled, while relevant database passwords were changed as part of the containment process.

Schools began receiving notifications on September 4th, followed by notifications to affected individuals. Mathspace also reported the incident to privacy and cybersecurity authorities in Australia and New Zealand, as well as Australian state and territory education departments.

The identity of the attackers remains unknown. Mathspace says it has found no evidence so far that the stolen information has been published, distributed, sold or otherwise misused.

The company is now reviewing why the original critical security advisory was not escalated and why recommended compromise checks were not completed when the Metabase installation was initially updated.

Leave a Reply