
Online math learning platform Mathspace announced over the weekend that attackers stole data from more than a million students, staff and parents after breaching its internal reporting system Metabase.
Founded in Sydney in 2010, Mathspace is now used by thousands of schools in Australia, New Zealand, the United States and the United Kingdom (3,432 in Australia and 3,557 overseas according to the company’s statistics in 2023).
In a blog post Saturday, Mathspace CTO Alvin Savoy said unknown attackers gained access to the company’s systems and stole personal information from school staff and students, as well as their parents and guardians.
“On September 3, 2026, we confirmed that unauthorized individuals had accessed a Mathspace internal reporting system and downloaded information about students, their parents or guardians, and school staff. Mathspace’s personnel files were also affected.” Savoy said.
“Attackers exploited a security vulnerability in our self-hosted installation of Metabase, a software we use for internal reporting. The vulnerability allowed attackers to gain administrative access to this system without a legitimate login.”
While the data breach was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace’s Australian reporting database on August 27.
Savoy noted that only the data of students and school staff from Australia and New Zealand was stolen in the incident. Although the attackers did not steal transcripts, academic records, and information, in some cases they may have been able to link some affected accounts to their schools.
“A total of 1,079,819 people were affected, including students, staff and parents or guardians combined. Only people in Australia and New Zealand were affected,” he added.
“No academic records, learning activities, scores, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools. However, for schools with identifiable email domains, we believe this may be possible.”
Savoy also warned affected students and school staff that attackers could target them with the stolen data and advised them to be alert for suspicious account-related activity such as changes to account details and password reset messages.
Metabase violations claimed by ShinyHunters
This breach comes on top of a series of other incidents that have impacted the Metabase instances of several other companies worldwide in the last month.
As BleepingComputer previously reported, threat actors exploited a critical zero-day Metabase SQL injection vulnerability to break into customer instances and steal data after gaining administrative access.
Trezor announced on August 13 that attackers stole the data of nearly 14,000 customers after hacking its shipping and logistics provider ShipMonk. It warned on Friday that the number of those affected has risen to 81,000.
Although Trezor has not yet attributed the attack to a specific threat actor or hacker group, BleepingComputer has learned that ShipMonk received extortion emails from the ShinyHunters extortion gang. ShinyHunters too Added metabase on August 11 to its dark web leak site.
Companies affected by this campaign include laptop maker Framework and online form creation platform Tally, which also disclosed data breaches after their Metabase instances were hijacked.
Previously, ShinyHunters was linked to breaches at more than a dozen Snowflake customers, Salesloft Drift and Salesforce Aura campaigns against hundreds of Salesforce customers, and over 100 corporate victims following data theft attacks that exploited an Oracle PeopleSoft zero-day vulnerability.
Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.
The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

