Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Mathspace Breach Exposes Data of More Than One Million Users
Mathspace Breach Exposes Data of More Than One Million Users
Read Time:3 Minute, 16 Second

Online mathematics platform Mathspace has disclosed a data breach affecting 1,079,819 students, parents, guardians, teachers and employees in Australia and New Zealand. Attackers accessed an internal reporting database and downloaded personal information after exploiting a critical vulnerability in the company’s self-hosted Metabase installation.

The Sydney-based education technology provider reported the incident on September 3. The scale makes it one of the region’s largest education-sector disclosures this year and raises particular concern because a substantial portion of the affected population consists of students.

Maximum-severity Metabase flaw was exploited quickly

The entry point was CVE-2026-72898, an unauthenticated SQL injection vulnerability in the password-reset API of the open-source Metabase business intelligence platform. An attacker could submit crafted database commands and obtain administrator-level access without valid credentials. The flaw received the maximum CVSS score of 10.0.

Metabase disclosed the actively exploited issue and released corrected versions on August 6. The US Cybersecurity and Infrastructure Security Agency soon added it to the Known Exploited Vulnerabilities catalog. Mathspace says unauthorized access to its Australian reporting database began on August 10, only four days after fixes became available, and data was removed on August 27.

The company did not update the affected installation until August 29, when a later notification brought the problem to its attention. Its existing vulnerability-alert process had failed to identify and escalate the original advisory. After patching, the company initially did not perform all of the recommended checks for systems that had remained exposed.

A review of historical access logs on September 3 finally confirmed that intrusion had occurred before remediation. The sequence shows why installing an update after active exploitation begins must trigger a compromise investigation rather than simply closing the ticket.

What information was downloaded

The exposed records varied by person but could include user IDs, usernames, names, email addresses, country and time-zone details, account types, email verification status, last-active and last-login dates, and account creation dates.

Mathspace says passwords, password hashes, single sign-on tokens, API credentials, assessments, academic results and learning-activity data were not included. The records did not directly connect accounts with particular schools, though identifiable institutional email domains could allow someone to infer that relationship.

The company says it has found no evidence that the information has been published, sold or misused. The identity of the attacker is unknown. Absence of observed misuse, however, is not a guarantee that copied data will remain dormant.

Notifications and defensive steps

Mathspace took the reporting system offline and notified schools, education departments and cybersecurity authorities. It began contacting school representatives on September 4 and says it is improving the way security advisories are escalated and the way teams verify systems after urgent patches.

  • Treat unexpected messages mentioning Mathspace, a school or the breach with caution.
  • Verify notices through the company’s official response channel instead of embedded links.
  • Avoid password reuse and review accounts for unusual reset attempts or sign-ins.
  • Schools should warn families that exposed identity details may make phishing more persuasive.

Lessons for software operators

The incident demonstrates that subscribing to advisories is not enough. Organizations need clear ownership, severity-based escalation and confirmation that critical alerts produce action. Internet-facing analytics and reporting tools also deserve accurate inventories and monitoring because they frequently hold broad, consolidated datasets.

When a flaw is known to be exploited, post-patch validation should cover the full vulnerable period. Teams should examine access logs, administrative changes, database queries and unusual exports, preserve evidence, and reset relevant secrets. In this case, the difference between the patch date and the later log review became the difference between assuming safety and discovering a million-person breach.

Education providers should further minimize what reporting platforms retain and restrict them from the public internet wherever possible. Segmentation, strong administrative authentication and export monitoring limit the damage if another analytics service is compromised.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Mathspace Breach Exposes Data of More Than One Million Users, use the discussion on Forum.

>> forum community

Comments

Leave a Reply