Mathspace breach exposes data on more than 1 million students, parents and staff

Attackers exploited a flaw in the maths platform's internal reporting tool, part of a wider campaign tied to the ShinyHunters extortion crew.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal editorial shot of a darkened enterprise server room, with one rack illuminated by amber warning light, reflecting faintly on p
Share

Key points

  • Mathspace confirmed on 3 September 2026 that attackers stole data on 1,079,819 students, parents, guardians and staff in Australia and New Zealand.
  • The hackers got in on 10 August and copied the Australian reporting database on 27 August.
  • The break-in used a flaw in Metabase, a self-hosted reporting tool sitting inside Mathspace's network.
  • No passwords, academic records, learning results or login tokens were taken.
  • The same Metabase flaw has been used against Trezor's shipping partner ShipMonk, laptop maker Framework and form platform Tally, with the ShinyHunters extortion gang claiming the campaign.

Sydney-based Mathspace, an online maths learning platform used by roughly 7,000 schools across Australia, New Zealand, the United States and the United Kingdom, told customers over the weekend that criminals had broken into an internal reporting system and taken personal information on more than a million people.

In a blog post on Saturday, chief technology officer Alvin Savoy said the intruders reached the data through a flaw in Metabase, a reporting tool the company runs on its own servers to pull charts and figures out of its databases. The bug let them hand themselves administrator access without ever logging in.

The numbers are stark. A total of 1,079,819 students, parents, guardians and school staff were affected, all of them in Australia or New Zealand.

What was actually stolen?

Contact-style personal information, not schoolwork or passwords. Mathspace says no academic records, learning activity, test results, password hashes (scrambled versions of passwords), authentication tokens or single sign-on credentials were exposed.

One caveat matters for schools. The stolen records do not name a child's school directly, but where a school uses an obvious email domain, someone reading the data could work out the link.

How did the hackers get in?

Through a known critical flaw in Mathspace's self-hosted Metabase installation. Metabase is business-intelligence software: staff use it to build internal dashboards and reports from company data. The bug being abused across this campaign is an SQL injection zero-day, meaning a database-query flaw the vendor did not know about when attacks began, that lets an outsider gain admin rights on the Metabase server.

Once in, the attackers could query the databases Metabase was pointed at, and pull the results down.

Timeline of the Mathspace incident

Date Event
10 August 2026 Attackers gain access to Mathspace systems
27 August 2026 Australian reporting database downloaded
3 September 2026 Mathspace confirms unauthorised access
Weekend of disclosure Public notice published by CTO Alvin Savoy

Should parents and school staff be worried?

Be alert, but do not panic. Mathspace is warning affected people that criminals may try to use the stolen details against them, so the sensible things to watch are password-reset emails you did not ask for, messages saying your account details have changed, and any unexpected contact that references your child's school or the Mathspace service.

If a message pushes you to click a link or hand over a code, treat it as suspect. Go to the service directly instead.

Who is behind the wider campaign?

The Metabase attacks have been claimed by ShinyHunters, a long-running extortion group that steals corporate data and pressures companies to pay to stop it being leaked or sold. The gang added Metabase to its dark-web leak site on 11 August, and, as first reported by BleepingComputer, has sent extortion emails in related cases.

Other victims of the same wave include cryptocurrency hardware-wallet maker Trezor, through its shipping and logistics provider ShipMonk. Trezor initially put the exposure at nearly 14,000 customers on 13 August, then revised the figure to 81,000 last Friday. Laptop maker Framework and form-building platform Tally have also confirmed breaches tied to hijacked Metabase servers.

ShinyHunters has been linked over the past two years to intrusions at more than a dozen Snowflake customers, the Salesloft Drift and Salesforce Aura campaigns hitting hundreds of Salesforce tenants, and over 100 companies breached through an Oracle PeopleSoft zero-day. No ransom figure has been reported publicly for the Mathspace intrusion, and the company has not said whether it has been contacted for payment.

© 2026 Threat Vectr