Mathspace confirms breach affecting 1.08 million amid wider wave of Metabase attacks

Online maths platform says attackers exploited a vulnerability in its self-hosted reporting system; no academic records or credentials exposed

edit
By LineZotpaper
Published
Updated
Read Time3 min
Sources2 outlets
Online maths learning platform Mathspace has confirmed that personal data belonging to 1,079,819 students, parents and school staff in Australia and New Zealand was stolen in a breach of its internal reporting system — the latest in a spate of attacks on Metabase, the open-source reporting tool the company used. Mathspace disclosed the incident over the weekend, saying the attacker gained administrator access to its self-hosted Metabase installation without a legitimate login.

Mathspace chief technology officer Alvin Savoy said in a blog post that unknown attackers first gained access to the company's systems on August 10 and downloaded data from its Australian reporting database on August 27. The theft was confirmed on September 3.

“Attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting,” Savoy wrote. “The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login.” ABC News reported the system was accessed during a period when a security patch had not been installed.

A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined, the company said. Exported data included user IDs, usernames, first and last names, email addresses, countries, time zones, user types, email-verification status, last-active date, last-login date and date joined — though not every affected person had all fields stolen.

Mathspace stressed that no academic records, learning activities, results, assessment records, passwords, authentication tokens, SSO credentials or API credentials were exposed, and that the data did not include records linking user accounts to their schools. However, Savoy noted that for schools with identifiable email domains, attackers may be able to make that link.

“We’re truly sorry this happened and are taking steps to prevent similar breaches in the future,” the company said. The compromised reporting system has been taken offline. Mathspace said it has contacted schools, cybersecurity authorities and education departments, and is now contacting affected individuals. It said it does not yet know who was responsible and has found “no evidence so far” that the stolen information has been published, shared or sold.

Savoy warned affected students and staff that attackers may target them using the stolen data, and advised watching for suspicious account-related activity such as changes to account details and password-reset messages. The company urged users to check unexpected messages independently, avoid disclosing passwords or verification codes in response to a message, and use a unique password for each account. Suspicious messages or activity can be reported to data-breach-response@mathspace.co.

The breach adds to a string of incidents involving Metabase instances at companies worldwide over the past month. BleepingComputer previously reported that threat actors exploited a critical Metabase SQL injection zero-day vulnerability to breach customer instances and steal data after gaining administrator access; the Metabase breaches have been claimed by the ShinyHunters threat group, according to the publication. Separately, hardware wallet maker Trezor revealed on August 13 that attackers stole data on nearly 14,000 customers after hacking its shipping and logistics provider ShipMonk, and warned on Friday that the number of affected individuals now reaches 81,000 customers.

Steve Hunter, director of engineering, APAC at cybersecurity firm Arctic Wolf, said the incident highlighted how difficult it can be for organisations to keep on top of software vulnerabilities. “Rather than playing ‘Whack-a-Mole’ every time a new vulnerability appears, organisations need to take a more risk-based approach,” he said. “The priority should be knowing what systems and software you have, understanding where the biggest risks sit, and having a clear process for acting when a critical security warning comes through.”

§

Analysis

Why This Matters

  • More than a million people are affected, many of them school students; stolen names, email addresses and account details could be used in targeted phishing and social-engineering campaigns.
  • Mathspace is one of several organisations hit through Metabase in recent weeks, signalling that a widely used open-source reporting tool has become a focus for attackers.
  • The breach is a reminder of the cost of delayed patching: the attackers accessed the system during a period when a security patch had not been installed.

Background

Mathspace, founded in Sydney in 2010, is an online maths learning platform used by thousands of schools across Australia, New Zealand, the United States and the United Kingdom. It ran a self-hosted installation of Metabase, an open-source business intelligence and reporting tool, for internal reporting. According to the company, the attacker exploited a vulnerability that granted administrator access without a legitimate login, entered the system on August 10, downloaded data on August 27, and was confirmed on September 3, with the breach disclosed over the weekend. Security reporting has documented a recent wave of attacks exploiting a critical Metabase SQL injection zero-day, with the breaches claimed by the ShinyHunters group.

Key Perspectives

Mathspace: The company has apologised, taken the reporting system offline and says it is notifying affected individuals, schools and authorities. It maintains that academic records and credentials were not exposed, and says there is no evidence the data has been published or sold.

Security experts: Steve Hunter of Arctic Wolf says the incident shows the limits of reactive patching. He argues organisations need a risk-based approach — knowing what systems they run, where the biggest risks sit, and having clear processes for acting on critical security warnings.

Affected students, families and schools: Users are advised to watch for suspicious messages and account activity, not to disclose passwords or verification codes in response to messages, and to use unique passwords, given attackers may use the stolen data for targeted fraud.

Critics and skeptics: The company's assurances are qualified — it does not yet know who was responsible, and it concedes that attackers may be able to link accounts to schools with identifiable email domains. The full impact may not be known until its investigation concludes.

What to Watch

  • Whether the stolen data appears for sale or is published online; Mathspace says there is “no evidence so far” of this.
  • Whether additional companies disclose breaches of their Metabase instances as the current attack wave continues.
  • Signs of phishing or fraud targeting students and school staff in Australia and New Zealand in the coming weeks.
  • Updates from Mathspace or the cybersecurity authorities and education departments it says it has contacted.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.