Mathspace, a prominent online mathematics platform, has revealed a significant data breach affecting more than one million individuals. The breach was identified last week, occurring approximately three weeks after the security of Mathspace’s self-hosted Metabase instance was compromised by attackers exploiting a known vulnerability.
Details of the Breach
The vulnerability, identified as CVE-2026-72898 with a maximum CVSS score of 10/10, pertains to an SQL injection flaw. This issue was patched on August 6, but not before it was exploited as a zero-day vulnerability. The hacking group ShinyHunters has claimed responsibility for the breach, targeting Metabase shortly after the patches were made available.
Despite the urgency of the situation, Mathspace delayed the critical advisory from Metabase. The platform only updated its system on August 29, more than two weeks post-attack. Unauthorized access was traced back to August 10, with data from the Australian database confirmed to be downloaded on August 27, according to Mathspace’s incident notice.
Security Measures and Response
Mathspace admitted shortcomings in escalating the advisory and conducting necessary compromise checks suggested by Metabase. The company is now revising its response procedures to prevent future incidents. In response to the breach, Mathspace has taken their Metabase instance offline, revoked API keys, disabled database access, changed passwords, and exported logs for further investigation.
The breach has impacted 1,079,819 students, teachers, staff, and guardians across Australia and New Zealand. The stolen data includes names, user IDs, usernames, email addresses, verification status, time zones, countries, join dates, and login activity. Importantly, no academic records or sensitive authentication data were compromised.
Impact and Precautions
Mathspace warns that the stolen information could be used in phishing attacks, advising those affected to be cautious of unsolicited communications referencing the breach. The incident has been reported to authorities in Australia, and notifications to potentially impacted individuals commenced over the weekend.
The data breach underscores the critical importance of timely security measures and proactive vulnerability management in safeguarding user information. As Mathspace works to enhance its security protocols, the incident serves as a stark reminder of the evolving threats in the digital landscape.
