Mathspace has confirmed a data breach affecting 1,079,819 students, parents, guardians and staff in Australia and New Zealand after attackers exploited a vulnerability in the company’s self-hosted Metabase reporting system.
The Sydney-based online mathematics learning platform confirmed the intrusion on Sept. 3 after reviewing historical access logs. Attackers had gained unauthorized access weeks earlier and downloaded information from Mathspace’s Australian reporting database on Aug. 27.
The exposed records contain names, email addresses and a range of account information. Mathspace said passwords, authentication credentials and academic records were not compromised.
Mathspace’s disclosure also identifies an internal security-process failure that left its Metabase installation vulnerable after a patch was already available. Metabase released fixes for the critical vulnerability on Aug. 6, but Mathspace did not install the update until Aug. 29, after the data had already been stolen.
Attackers gained administrator access through Metabase
According to Mathspace’s incident disclosure, attackers exploited a vulnerability in the company’s self-hosted installation of Metabase, which it used for internal reporting.
The vulnerability allowed an attacker to obtain administrator access without a legitimate login.
Mathspace’s investigation identified unauthorized access dating back to Aug. 10, Australian Eastern Standard Time. The company confirmed that information was downloaded from its Australian reporting database on Aug. 27.
Metabase had released a critical security advisory and patched versions 4 days before the earliest unauthorized access identified by Mathspace.
Mathspace acknowledged that its existing vulnerability-notification process failed to identify and escalate the Aug. 6 advisory. A subsequent Metabase notice came to the company’s attention and Mathspace updated its installation on Aug. 29.
By then, the data theft had already occurred.
Mathspace also said it did not initially complete additional compromise checks recommended for potentially affected systems when it applied the update. A later review of historical access logs led the company to confirm the unauthorized activity on Sept. 3.
More than 1 million students, families and staff affected
Mathspace determined that 1,079,819 people were affected across Australia and New Zealand. The total includes students, parents or guardians, teachers and Mathspace employees.
Depending on the individual record, the stolen information includes:
- User IDs and usernames
- First and last names
- Email addresses
- Country and time zone information
- User type
- Email verification status
- Last active and last login dates
- Account creation dates
Not every affected record contained every data field.
Mathspace said no academic records, learning activities, results or assessment records were exposed. Password hashes, authentication tokens, single sign-on credentials and API credentials were also not included in the stolen information.
The exported records did not directly associate user accounts with individual schools. However, Mathspace acknowledged that an individual’s school may still be identifiable when an affected account uses a recognizable school email domain.
Former and inactive users may also be affected because records retained in the reporting database were included regardless of whether an account remained active.
Metabase zero-day enabled administrator sessions
The Mathspace intrusion occurred during a broader series of attacks exploiting a previously unknown vulnerability in Metabase.
In an August technical postmortem, Metabase said it discovered the zero-day after investigating suspicious API key creation on customer instances beginning Aug. 3.
The attack chain involved a SQL injection vulnerability associated with the password-reset functionality. Metabase said attackers could exploit the flaw to create a valid administrator session and then browse accessible data and generate an API key for bulk downloads.
Metabase said installations running version 0.58 and later were vulnerable. Fewer than 3% of its cloud customers were compromised before Metabase deployed patches, while some publicly accessible self-hosted and open-source installations were also affected.
The company released patched versions on Aug. 6.
Mathspace’s timeline shows that its self-hosted instance remained unpatched when unauthorized access began on Aug. 10 and was still vulnerable when information was downloaded on Aug. 27.
Mathspace takes reporting system offline
After confirming the breach on Sept. 3, Mathspace took its Metabase reporting system offline, revoked all Metabase API keys and disabled the platform’s database-access accounts in its Australian and U.S. Snowflake environments.
The company also changed passwords associated with its Metabase Cloud SQL databases and preserved the application database and access logs for further investigation.
Metabase remained offline while Mathspace continued recovery and compromise checks at the time of its latest update.
Mathspace said it is reviewing why the initial security advisory was not escalated and why the recommended compromise checks were not completed when the software was eventually updated. The company said both processes are being changed as part of its response.
Australian and New Zealand authorities notified
Mathspace reported the incident on Sept. 4 to Australia’s Office of the Australian Information Commissioner and the Australian Signals Directorate’s Australian Cyber Security Centre.
The company also notified New Zealand’s Office of the Privacy Commissioner and National Cyber Security Centre, along with Australian state and territory education departments.
Schools began receiving notifications on Sept. 4. Mathspace subsequently moved forward its notification schedule after schools requested that affected individuals be informed sooner and began sending individual notifications on Sept. 6.
Mathspace said it has completed its investigation into the scope of the exposure and identified the affected accounts and records. The identity of the attacker remains unknown.
No evidence of stolen data being published
Mathspace said it has found no evidence that the stolen information has been published, distributed, sold or otherwise misused.
However, the combination of names, email addresses, account types and activity information creates a risk of targeted phishing and impersonation, particularly because the affected population includes students, parents and school staff.
The company warned users to be cautious of unexpected communications even when messages contain accurate personal information or references to Mathspace or their school.
Mathspace is not requiring password resets because authentication credentials were not exposed. It nevertheless advised users who reused their Mathspace password elsewhere to replace those reused passwords with unique credentials.
The incident is another confirmed breach stemming from the August Metabase vulnerability, which has been exploited against multiple organizations. While other Metabase-related incidents have been associated with ShinyHunters extortion activity, Mathspace said the identity of the attacker responsible for its breach remains unknown.











