Online learning platform Mathspace has disclosed a major data breach affecting more than one million students, parents, guardians and staff members. Attackers stole the information after compromising the company’s internal reporting system.
The incident affected 1,079,819 people in Australia and New Zealand. However, Mathspace said the attackers did not obtain passwords, authentication credentials or academic records.
Mathspace provides online mathematics education to thousands of schools across Australia, New Zealand, the United States and the United Kingdom.
Attackers breached internal reporting system
Mathspace confirmed the data theft on September 3, according to chief technology officer Alvin Savoy. The attackers initially accessed the company’s systems on August 10.
They later downloaded information from Mathspace’s Australian reporting database on August 27.
The attackers exploited a vulnerability in Mathspace’s self-hosted Metabase installation. The company uses the analytics platform for internal reporting.
The security flaw allowed the attackers to gain administrator access without entering legitimate login credentials. They then downloaded personal information belonging to students, parents, guardians and school staff. Records concerning Mathspace employees were also affected.
Breach exposed personal information
The Mathspace data breach affected people in Australia and New Zealand only. The company has not reported exposure involving users in other countries.
Mathspace said the stolen information did not include academic records, learning activities, assessment results or passwords. Attackers also failed to obtain password hashes, authentication tokens, single sign-on credentials or API credentials.
In addition, the exposed database did not directly connect user accounts to individual schools. However, attackers may still identify some schools through distinctive email domains.
This information could support targeted phishing and social engineering campaigns. Therefore, Mathspace advised affected users to monitor their accounts for unusual activity.
Warning signs may include unexpected changes to account details or unsolicited password-reset messages. Users should also avoid clicking links in suspicious emails that claim to come from Mathspace or their school.
Metabase zero-day linked to multiple breaches
The incident forms part of a broader series of attacks targeting Metabase installations. Threat actors reportedly exploited a critical SQL injection zero-day vulnerability to compromise customer systems.
The flaw allowed attackers to gain administrator access and steal information from affected Metabase instances.
Other victims include laptop manufacturer Framework and online form-building service Tally. Both companies disclosed breaches after attackers compromised their Metabase systems.
Cryptocurrency hardware wallet maker Trezor also linked a recent breach at logistics provider ShipMonk to a compromised Metabase installation. Trezor initially reported that the incident affected almost 14,000 customers. It later increased the total to 81,000.
ShinyHunters claims Metabase campaign
The ShinyHunters extortion group has claimed responsibility for attacks involving Metabase. The group added the analytics software provider to its dark web leak site on August 11.
ShipMonk also reportedly received extortion emails from ShinyHunters. However, neither Trezor nor Mathspace has publicly attributed its breach to a specific cybercrime group.
ShinyHunters has previously appeared in campaigns involving Snowflake customers, Salesloft Drift and Salesforce Aura. The group has also targeted Oracle PeopleSoft servers by exploiting a zero-day vulnerability.
The scale of the Mathspace data breach makes it one of the largest incidents connected to the recent Metabase campaign. Affected students, families and staff should remain cautious of messages that use stolen personal information to appear legitimate.


0 responses to “Mathspace data breach affects over 1 million people”