Mathspace Breach Exposes Data on 1.08 Million Students
Security / news
Mathspace Breach Exposes Data on 1.08 Million Students
Attackers had 17 days between reaching Mathspace's reporting database and downloading it, and the company patched the underlying Metabase flaw only after both had happened.

Attackers reached administrator access on Mathspace's self-hosted Metabase instance on Aug. 10 without a valid login, exploiting a flaw the analytics vendor had already patched four days earlier. The Sydney-based education technology company said Sept. 3 that the intrusion exposed records on 1,079,819 students, parents and staff across Australia and New Zealand.
"Attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting," Mathspace said in its own account of the breach. "The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login."
The four-day window Mathspace did not close
Metabase published a critical, maximum-severity advisory rated 10.0 on the CVSS scale on Aug. 6 and shipped a patch the same day. Mathspace did not apply that patch until Aug. 29, according to its own timeline, 23 days after it was available and two days after the attacker had already copied its data. Unauthorized access to the Australian reporting database began Aug. 10, four days into that gap.
Seventeen days between access and download
The attacker sat inside the system for more than two weeks before acting: BleepingComputer's reporting and Mathspace's own timeline both place the data download on Aug. 27, 17 days after the initial, unauthenticated access on Aug. 10. Mathspace confirmed the breach and took the reporting system offline on Sept. 3, and began notifying individuals Sept. 6.
What was taken, and what was not
The exposed fields were limited to account metadata: user IDs, usernames, first and last names, email addresses, country, time zone, user type, email-verification status, and the last-active, last-login and date-joined fields. Mathspace said passwords, single sign-on tokens, other authentication credentials, academic records and assessment data were not exposed, and BleepingComputer's independent reporting on the incident did not contradict that account.
Mathspace's response
Mathspace said it took the reporting system offline, revoked the API keys and disabled the database accounts tied to the intrusion, and changed the passwords protecting the affected databases. The company said it has notified Australia's Office of the Australian Information Commissioner and New Zealand's Privacy Commissioner. Mathspace's own account of the breach was first published Sept. 5 and updated Sept. 8; BleepingComputer's independent report followed Sept. 7, citing the same timeline of dates the company later confirmed.
| Date | Event |
|---|---|
| Aug. 6, 2026 | Metabase publishes a CVSS-10.0 advisory and ships a patch |
| Aug. 10, 2026 | Unauthorized access to Mathspace's Metabase instance begins |
| Aug. 27, 2026 | Attacker downloads the Australian reporting database |
| Aug. 29, 2026 | Mathspace applies the Metabase patch |
| Sept. 3, 2026 | Mathspace confirms the breach, takes the system offline |
| Sept. 6, 2026 | Individual notifications begin |
It joins CenterPoint Energy's breach disclosure and Veradigm's third breach in two years as a reminder that a patch sitting on a vendor's advisory page does nothing by itself. Veradigm's incident traced back to a vendor credential nobody revoked; Mathspace's traced back to a patch nobody applied for 23 days after it existed.
Sources
More in Security
- 01WordPress 7.1.1 Closes the Click2Shell Remote Code ChainResearcher Paulos Yibelo's chain turned one clicked link into server-side code execution by tricking WordPress into silently installing a theme with no authorization checks at all.
- 02Oracle's September Update Fixes Six Perfect-10 BugsNone of the maximum-severity flaws is confirmed under attack yet, but Oracle is now shipping security patches on a monthly rather than strictly quarterly calendar.
- 03BragJack Hijacks AI Agents Built Into Five BrowsersA single malicious extension could seize Chrome's Gemini, Edge's Copilot, Opera Neon, Perplexity Comet and Claude in Chrome without bypassing any model's guardrails or writing a single injected prompt.
- 04Two Days After a Patch, Red Heron Scanned 1,386 Gitea ServersAcronis says the Chinese-speaking group turned a fixed Gitea flaw into a rootkit-based campaign that compromised organizations in five countries within a week.