CSIDB logo
Incident

Mathspace

Incident posture

Attack window
Aug 2026
Location
Australia
Status
Unknown
CIA posture
Available to members
Updated
2026-09-07 16:39

Linked entities

Victim
Mathspace
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An unauthorised party exploited an unpatched vulnerability in a self-hosted installation of Metabase, an internal business intelligence tool, to gain access to Mathspace's Australian reporting database and download records covering roughly 1.08 million students, parents or guardians, school staff, and the company's own employees located in Australia and New Zealand. The exposed information included names, email addresses, user types, account activity timestamps, and date-joined records, while passwords, SSO tokens, academic records, and payment details were not compromised. The company disclosed the incident publicly after a roughly three-week gap during which the vendor patch went unapplied, and it reported the matter to regulators while beginning individual notifications. Affected data has not yet been observed published, distributed, or sold, though the combination of verified contact details and role classifications creates notable phishing and social-engineering risk for the involved families and schools.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 10, 2026 (Australian Eastern Standard Time), unauthorised parties began accessing an internal reporting system operated by Mathspace, an online maths tutoring platform used by schools across Australia and New Zealand. The platform builds adaptive maths practice software adopted by schools for classroom and homework use, and its user base skews toward minors. Cyber Daily reported that the entry point was an unpatched vulnerability in Mathspace's self-hosted installation of Metabase, an open-source business intelligence tool many companies use to build internal dashboards. Metabase had issued a critical security advisory and released patches around August 6, 2026, several days before unauthorised access commenced on the Mathspace instance. According to The Cyber Express, the flaw allowed administrator-level access without legitimate credentials, letting attackers treat the internal reporting tool as an open door into the underlying data rather than needing to breach the core Mathspace application or its authentication system separately.

The attacker or attackers downloaded information from Mathspace's Australian reporting database on August 27, 2026, according to the company's own account. The download occurred roughly two days before Mathspace applied the Metabase update internally on August 29, 2026, leaving a multi-week window during which the vulnerable instance remained reachable. Mathspace confirmed the data set downloaded from its reporting database included the following fields: user ID, username, first name, last name, email address, country, time zone, user type, email-verification status, last-active date, last-login date, and date joined. The exposed information included names and email addresses across the affected accounts, along with those account details. Mathspace's disclosure stated that customer passwords, single sign-on (SSO) tokens, and other customer authentication credentials were not exposed, and that no academic or learning data was compromised, meaning grades, assignment history, and problem-solving records tied to individual students appear to have stayed outside the reporting system the attacker accessed.

Mathspace disclosed the incident publicly on September 3, 2026, and last updated its public notice on September 6, 2026. The company reported the incident to regulators on September 4, 2026, and began notifying affected individuals on September 6, 2026, per The Cyber Express's reporting. The breach affected 1,079,819 people, a figure that includes students, their parents or guardians, school staff, and Mathspace's own employees. Cyber Daily framed the count as more than 1 million Australians and New Zealanders, and Mathspace said only people located in Australia and New Zealand were affected, narrowing the geographic footprint. The company has not broken down how many people fall into each of the four categories, so it is not yet possible to say what share of the total are minors versus adults. Mathspace is privately held, so there is no public stock reaction to measure.

The company opened its public statement with an apology, writing: "We're truly sorry this happened and are taking steps to prevent similar breaches in the future." Mathspace's disclosure lays out what was and was not exposed in plain terms, stating that "the exposed information included names and email addresses, along with account details described below." As for whether the stolen records have leaked further, Mathspace's position, according to its own disclosure, is that "we have no evidence so far that the data has been published, distributed, sold or otherwise misused." The company has not named the attacker or described a motive, and it has not published a named executive quote beyond these company-level statements or a technical root-cause report detailing exactly how the Metabase instance was exposed to the public internet in the first place.

Because the affected population sits in Australia and New Zealand, Mathspace's obligations run through Australia's Notifiable Data Breaches scheme, administered by the Office of the Australian Information Commissioner, which requires organisations to report eligible data breaches and notify affected individuals when the breach is likely to result in serious harm. New Zealand runs a parallel notification requirement under its own Privacy Act. Mathspace has not disclosed any regulatory findings beyond confirming it notified authorities, and whether the company faces a formal investigation, a fine, or simply a compliance review is not yet confirmed. Nothing has been filed as of the available reporting, though Australian media has followed the pattern set by other 2026 breach settlements, and at least one class-action or consumer-protection inquiry may be floated. The combination of names, verified emails, account activity timestamps, and user-type classification (student, parent, or staff) is enough to build a fairly precise profile of who uses Mathspace, how recently, and in what role, even without a single password in the mix.

Sources

Sources available to members: 1 source.

CSIDB