# Mathspace Breach: Over 1 Million Impacted by Metabase Zero-Day

> Mathspace disclosed a data breach affecting over 1 million students, staff, and parents due to a Metabase vulnerability.

- Published: 2026-09-07T13:49:42.000Z
- Severity: high
- Category: Data Breach
- Tags: Data Breach, SQL Injection, ShinyHunters, Zero-Day, Mathspace
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/
- Canonical: https://runtimerebel.com/blog/mathspace-breach-over-1-million-impacted-by-metabase-zero-day

## Key points

- Over 1 million Mathspace users in Australia and New Zealand had personal data stolen.
- Mathspace's self-hosted Metabase internal reporting system was exploited via a zero-day vulnerability.
- Monitor for suspicious account activity and unsolicited password reset requests.

Mathspace, an online mathematics learning platform, has disclosed a significant [data breach](/glossary#data-breach) impacting over 1 million students, staff, and parents across Australia and New Zealand. The breach, confirmed on September 3, 2026 (as per Mathspace's CTO statement), resulted from attackers exploiting a security [vulnerability](/glossary#vulnerability) in the company's self-hosted Metabase internal reporting system.

## Technical Details of the Mathspace Data Breach

### Exploitation of Metabase Vulnerability
According to [BleepingComputer](https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/), the threat actors gained unauthorized access to Mathspace's systems on August 10 and subsequently downloaded data from the company's Australian reporting database on August 27. Mathspace CTO Alvin Savoy confirmed that the attackers leveraged a vulnerability in their self-hosted Metabase instance, allowing them to obtain administrator access without requiring legitimate login credentials. This method of compromise aligns with a pattern of attacks observed against other companies utilizing Metabase.

### Scope and Impact on Users
A total of 1,079,819 individuals were affected, comprising students, school staff, and their parents or guardians. Crucially, only individuals located in Australia and New Zealand had their data compromised in this incident. Mathspace has clarified that no academic records, learning activities, results, assessment records, passwords (including hashes), authentication tokens, [SSO](/glossary#sso) credentials, or [API](/glossary#api) credentials were exposed. Furthermore, the exposed data did not include records directly linking user accounts to their respective schools. However, for schools utilizing identifiable email domains, Mathspace acknowledges that linking accounts may still be possible for the attackers. The primary risk to affected individuals is potential future targeting via [social engineering](/glossary#social-engineering) or [phishing](/glossary#phishing) attacks using the stolen personal information.

### The Broader Metabase [Zero-Day](/glossary#zero-day) Campaign and ShinyHunters Activity
This incident is not isolated; it is part of a broader campaign targeting Metabase instances globally. BleepingComputer has previously reported on threat actors exploiting a critical Metabase SQL injection zero-day vulnerability to breach customer instances and exfiltrate data after gaining administrator access. Other organizations affected in this campaign include laptop maker Framework and online form-building platform Tally. Notably, the [ShinyHunters](https://en.wikipedia.org/wiki/ShinyHunters) extortion gang has been linked to similar Metabase-related breaches, including one affecting Trezor's shipping provider, ShipMonk, with ShinyHunters adding Metabase to their [dark web](/glossary#dark-web) leak site on August 11.

This wider context highlights the urgency for organizations using Metabase to address potential vulnerabilities, especially when considering **Metabase SQL injection zero-day vulnerability** as a persistent threat vector. Understanding the common TTPs used in the **ShinyHunters Metabase campaign** provides valuable intelligence for defenders.

## Actionable Recommendations for Defenders
For organizations and individuals concerned about the **Mathspace data breach mitigation steps** and the broader Metabase vulnerability campaign, the following actions are crucial:

*   **For Mathspace Users (Australia and New Zealand):**
    *   Remain vigilant for suspicious account-related activity, such as unauthorized changes to personal details or unexpected password-reset messages.
    *   Exercise extreme caution with unsolicited emails or communications that appear to originate from Mathspace or educational institutions, as these could be phishing attempts using the stolen data.

*   **For Organizations Using Self-Hosted Metabase Instances:**
    *   Immediately review and apply all available security patches and updates for your Metabase deployments. Prioritize patches addressing SQL injection vulnerabilities.
    *   Conduct a thorough audit of Metabase access logs for any unauthorized administrator access or unusual [data exfiltration](/glossary#data-exfiltration) activities, particularly around the August-September timeframe mentioned in the Mathspace incident.
    *   Implement strict [network segmentation](/glossary#network-segmentation) to isolate internal reporting systems like Metabase from critical production environments and sensitive data stores.
    *   Enhance monitoring for unusual activity originating from Metabase instances, including large data transfers or connections to suspicious external [IPs](/glossary#ips).
    *   Consider implementing Web Application Firewalls (WAFs) and Intrusion Prevention Systems (IPS) to detect and block common web-based attack vectors, including SQL injection attempts.
    *   Perform regular [penetration testing](/glossary#penetration-testing) and vulnerability assessments on all publicly accessible or internal systems, including reporting platforms, to identify and remediate weaknesses before they can be exploited.

**Related:** [Nissan Breach: Oracle PeopleSoft Zero-Day Exploited by ShinyHunters](/blog/nissan-breach-oracle-peoplesoft-zero-day-exploited-by-shinyhunters), [ShinyHunters Breach NAIC via PeopleSoft Zero-Day: Public Data Stolen](/blog/shinyhunters-breach-naic-via-peoplesoft-zero-day-public-data-stolen)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/mathspace-breach-over-1-million-impacted-by-metabase-zero-day
