Mathspace Data Breach Exposes Over 1 Million Users in Australia and New Zealand
Australian edtech platform Mathspace has disclosed a data breach affecting more than 1.07 million students, parents, teachers, and staff across Australia and New Zealand. The incident, confirmed on September 3, 2026, stemmed from an unpatched vulnerability in the company’s self-hosted Metabase reporting system.
The breach occurred after an attacker exploited a known flaw in Metabase, disclosed on August 6, 2026, which Mathspace failed to address due to an internal oversight in its vulnerability notification process. Unauthorized access began as early as August 10, with data exfiltrated on August 27, before the company detected the intrusion on September 3.
Exposed data included names, email addresses, user IDs, usernames, account creation dates, last login timestamps, and email verification statuses though passwords, SSO tokens, and authentication credentials remained secure. No academic or learning data was compromised. Mathspace has since taken its platform offline to remediate the issue and has notified regulators, including Australia’s OAIC and ACSC, as well as New Zealand’s Privacy Commissioner and NCSC.
The company is conducting a post-incident review to improve its vulnerability management and response processes. Notifications to affected individuals began on September 6, with no threat actor yet claiming responsibility.
Metabase TPRM report: https://www.rankiteo.com/company/metabase
Mathspace TPRM report: https://www.rankiteo.com/company/mathspace
"id": "metmat1788740628",
"linkid": "metabase, mathspace",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1.07 million students, parents, '
'teachers, and staff',
'industry': 'Education Technology',
'location': 'Australia and New Zealand',
'name': 'Mathspace',
'type': 'EdTech Platform'}],
'attack_vector': 'Exploitation of unpatched vulnerability',
'customer_advisories': 'Notifications to affected individuals began on '
'September 6, 2026',
'data_breach': {'data_encryption': 'No (passwords, SSO tokens, and '
'authentication credentials remained '
'secure)',
'data_exfiltration': 'Yes (occurred on August 27, 2026)',
'number_of_records_exposed': '1.07 million',
'personally_identifiable_information': 'Names, email '
'addresses, user IDs, '
'usernames, account '
'creation dates, last '
'login timestamps, '
'email verification '
'statuses',
'sensitivity_of_data': 'Moderate (names, email addresses, '
'user IDs, usernames, account creation '
'dates, last login timestamps, email '
'verification statuses)',
'type_of_data_compromised': 'Personally Identifiable '
'Information (PII)'},
'date_detected': '2026-09-03',
'date_publicly_disclosed': '2026-09-03',
'description': 'Australian edtech platform Mathspace has disclosed a data '
'breach affecting more than 1.07 million students, parents, '
'teachers, and staff across Australia and New Zealand. The '
'incident stemmed from an unpatched vulnerability in the '
'company’s self-hosted Metabase reporting system, which was '
'exploited by an attacker.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'breach',
'data_compromised': 'Names, email addresses, user IDs, usernames, '
'account creation dates, last login '
'timestamps, email verification statuses',
'downtime': 'Platform taken offline for remediation',
'identity_theft_risk': 'Potential risk due to exposed PII',
'operational_impact': 'Platform offline during remediation',
'systems_affected': 'Self-hosted Metabase reporting system'},
'initial_access_broker': {'entry_point': 'Unpatched Metabase vulnerability'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Improvement needed in vulnerability management and '
'response processes',
'post_incident_analysis': {'corrective_actions': 'Post-incident review to '
'improve vulnerability '
'management and response '
'processes',
'root_causes': 'Failure to patch known Metabase '
'vulnerability due to internal '
'oversight in vulnerability '
'notification process'},
'recommendations': 'Enhance vulnerability patching processes, conduct regular '
'security audits, improve internal notification systems '
'for vulnerabilities',
'references': [{'source': 'Mathspace Disclosure'}],
'regulatory_compliance': {'regulatory_notifications': 'OAIC (Australia), ACSC '
'(Australia), Privacy '
'Commissioner (New '
'Zealand), NCSC (New '
'Zealand)'},
'response': {'communication_strategy': 'Notifications to affected individuals '
'began on September 6, 2026',
'containment_measures': 'Platform taken offline for remediation',
'remediation_measures': 'Patching the Metabase vulnerability, '
'post-incident review'},
'stakeholder_advisories': 'Regulators notified (OAIC, ACSC, Privacy '
'Commissioner, NCSC)',
'title': 'Mathspace Data Breach Exposes Over 1 Million Users in Australia and '
'New Zealand',
'type': 'Data Breach',
'vulnerability_exploited': 'Known flaw in Metabase (disclosed on August 6, '
'2026)'}