More than one million individuals in Australia and New Zealand have been affected by a significant data breach at Mathspace, an online mathematics learning platform. The breach occurred when attackers exploited a critical flaw in the company’s internal reporting software, compromising sensitive user information.
Details of the Breach
Sydney-based Mathspace disclosed on 3 September 2026 that unauthorized parties accessed its internal reporting system. This breach impacted students, parents, guardians, and school staff, totaling 1,079,819 affected individuals. This event has become one of the largest reported breaches in the education sector within the region this year.
The breach was facilitated through a vulnerability in Mathspace’s self-hosted Metabase installation, a business intelligence tool used for internal reporting. Identified as CVE-2026-72898, this flaw allowed attackers to execute arbitrary SQL commands through an unauthenticated SQL injection, gaining administrator access without valid credentials.
Response and Impact
Although Metabase released a patch for the vulnerability on 6 August 2026, Mathspace did not apply it promptly. The company acknowledged that its process for handling vulnerability notifications failed to escalate the advisory for action. Consequently, unauthorized access began on 10 August, and data exfiltration occurred on 27 August.
The compromised data included user IDs, names, email addresses, and other account-related metadata. However, Mathspace assured that critical credentials, such as passwords, SSO tokens, and academic records, were not exposed. There is no evidence thus far that the stolen data has been misused or made public.
Preventive Measures and Future Steps
In response, Mathspace has taken the affected reporting system offline and is revising its processes to prevent future incidents. The company has communicated the breach to school contacts, urging them to verify suspicious communications through official channels. Furthermore, Mathspace is working with cybersecurity authorities to enhance its security measures.
Affected individuals are advised to remain vigilant, monitor accounts for unusual activity, and avoid reusing passwords across different services. Mathspace’s proactive measures aim to restore trust and prevent similar breaches in the future.
For further details, Mathspace encourages users to stay informed through its data-breach response channels.
