Mathspace, an online educational platform specializing in mathematics, recently revealed a significant data breach that has impacted over one million people. The breach was traced back to a vulnerability in their self-hosted Metabase system, which hackers exploited approximately three weeks before Mathspace discovered the incident. The vulnerability, identified as CVE-2026-72898 with a critical severity score of 10 out of 10, involved an SQL injection flaw that had been exploited as a zero-day before a patch was released on August 6. Not long after, the cybercriminal group ShinyHunters claimed responsibility for the attack.
Mathspace acknowledged a delay in responding to the critical advisory related to the vulnerability, only upgrading their Metabase instance on August 29, weeks after the breach. The unauthorized access was traced back to August 10, and data extraction from Mathspace's Australian reporting database occurred on August 27. The company admitted to not completing the recommended compromise checks immediately after applying the update.
To mitigate the situation, Mathspace has taken several steps. They have taken their Metabase instance offline, revoked API keys, disabled database access accounts, changed passwords, and are conducting a thorough investigation using exported logs. The breach affects 1,079,819 individuals, including students, teachers, staff, and parents or guardians in Australia and New Zealand. Exposed information includes names, user IDs, email addresses, and login details, but thankfully no academic records or sensitive credentials were compromised.
Mathspace has warned affected individuals to be vigilant against potential phishing attacks that might use the leaked information. The company has reported the incident to relevant authorities in Australia and has started notifying those impacted by the breach.

