Mathspace Data Breach Exposes Over 1 Million People
Mathspace, an online mathematics platform, suffered a data breach impacting over 1 million individuals due to exploitation of a critical SQL injection vulnerability (CVE-2026-72898) in its self-hosted Metabase instance. The breach involved unauthorized access and data exfiltration of personal information including names, user IDs, usernames, email addresses, and related metadata of students, teachers, staff, and parents/guardians primarily from Australia and New Zealand. No sensitive academic records, passwords, or authentication credentials were exposed. The incident was discovered weeks after exploitation began, and remediation was delayed beyond the patch release date. Mathspace has taken steps to secure the environment and is investigating the incident while notifying affected individuals.
AI Analysis
Technical Summary
Mathspace's self-hosted Metabase instance was compromised via a known critical SQL injection vulnerability (CVE-2026-72898, CVSS 10.0) exploited as a zero-day before patching. The attackers gained unauthorized access starting August 10, 2026, and downloaded personal data of 1,079,819 users by August 27. The exposed data included identifying information such as names, user IDs, email addresses, and login metadata, but excluded academic records, passwords, authentication tokens, and API credentials. Mathspace delayed patching until August 29, after the breach had occurred, and did not complete recommended compromise checks. The breach was claimed by the extortion group ShinyHunters. Mathspace has since taken the Metabase instance offline, revoked API keys, disabled database accounts, changed passwords, and is conducting a forensic investigation.
Potential Impact
The breach exposed personal identifying information of over one million users, including students, teachers, staff, and parents/guardians, which could facilitate phishing or social engineering attacks. No sensitive academic or authentication data was compromised, reducing the risk of direct account takeover or academic fraud. The delayed patching and incomplete incident response increased exposure duration and risk. The breach affects privacy and may lead to targeted phishing campaigns against affected individuals.
Mitigation Recommendations
Mathspace has taken the affected Metabase instance offline, revoked API keys, disabled database access accounts, changed passwords, and exported logs for investigation. The critical SQL injection vulnerability (CVE-2026-72898) was patched on August 6, 2026. Organizations using Metabase should ensure they apply this patch promptly and perform recommended compromise checks. Affected individuals should be cautious of phishing attempts referencing this breach. No further immediate action is indicated as the vulnerability is patched and the compromised system has been secured.
Affected Countries
Australia, New Zealand
Mathspace Data Breach Exposes Over 1 Million People
Description
Mathspace, an online mathematics platform, suffered a data breach impacting over 1 million individuals due to exploitation of a critical SQL injection vulnerability (CVE-2026-72898) in its self-hosted Metabase instance. The breach involved unauthorized access and data exfiltration of personal information including names, user IDs, usernames, email addresses, and related metadata of students, teachers, staff, and parents/guardians primarily from Australia and New Zealand. No sensitive academic records, passwords, or authentication credentials were exposed. The incident was discovered weeks after exploitation began, and remediation was delayed beyond the patch release date. Mathspace has taken steps to secure the environment and is investigating the incident while notifying affected individuals.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Mathspace's self-hosted Metabase instance was compromised via a known critical SQL injection vulnerability (CVE-2026-72898, CVSS 10.0) exploited as a zero-day before patching. The attackers gained unauthorized access starting August 10, 2026, and downloaded personal data of 1,079,819 users by August 27. The exposed data included identifying information such as names, user IDs, email addresses, and login metadata, but excluded academic records, passwords, authentication tokens, and API credentials. Mathspace delayed patching until August 29, after the breach had occurred, and did not complete recommended compromise checks. The breach was claimed by the extortion group ShinyHunters. Mathspace has since taken the Metabase instance offline, revoked API keys, disabled database accounts, changed passwords, and is conducting a forensic investigation.
Potential Impact
The breach exposed personal identifying information of over one million users, including students, teachers, staff, and parents/guardians, which could facilitate phishing or social engineering attacks. No sensitive academic or authentication data was compromised, reducing the risk of direct account takeover or academic fraud. The delayed patching and incomplete incident response increased exposure duration and risk. The breach affects privacy and may lead to targeted phishing campaigns against affected individuals.
Defensive Guidance
Mathspace has taken the affected Metabase instance offline, revoked API keys, disabled database access accounts, changed passwords, and exported logs for investigation. The critical SQL injection vulnerability (CVE-2026-72898) was patched on August 6, 2026. Organizations using Metabase should ensure they apply this patch promptly and perform recommended compromise checks. Affected individuals should be cautious of phishing attempts referencing this breach. No further immediate action is indicated as the vulnerability is patched and the compromised system has been secured.
Affected Countries
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/mathspace-data-breach-exposes-over-1-million-people/","fetched":true,"fetchedAt":"2026-09-08T10:52:16.847Z","wordCount":1047}
Threat ID: 6a9fe8e1acd9273b49823d16
Added to database: 09/08/2026, 10:52:17 UTC
Last enriched: 09/08/2026, 10:52:22 UTC
Last updated: 09/08/2026, 11:29:29 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.