Mathspace disclosed that unauthorized parties accessed its internal reporting system and downloaded account and contact metadata for 1,079,819 people in Australia and New Zealand, including students, parents or guardians, teachers, and employees. The intrusion was reportedly enabled by CVE-2026-72898, a critical unauthenticated SQL-injection vulnerability in a self-hosted Metabase instance, which allegedly gave attackers administrator access.
The education platform said passwords and hashes, SSO tokens, API credentials, academic records, grades, and learning-activity data were not exposed. Mathspace took the reporting system offline, notified affected schools, education departments, and cybersecurity authorities, and said it is strengthening vulnerability-advisory escalation and post-patch validation processes.

See attribution, scope, and your downstream exposure.
9 events from the most recent confirmed update back to the earliest known activity.
Mathspace published an official disclosure of the Metabase-related breach affecting 1,079,819 people, describing the exposed account metadata and stating that passwords, credentials, SSO tokens, academic records, and API tokens were not exposed. It reported containment measures including revoking Metabase API keys, disabling Metabase access to Snowflake environments, changing Cloud SQL passwords, and preserving logs and application-database evidence for investigation.
Mathspace began emailing school contacts about the data breach.
A review of historical access logs confirmed unauthorized access had occurred before the Metabase patch was applied. Mathspace confirmed the security incident affecting 1,079,819 people in Australia and New Zealand.
Mathspace updated the self-hosted Metabase instance affected by CVE-2026-72898. The company did not initially perform additional compromise checks recommended for systems exposed during the vulnerable period.
Attackers downloaded data from Mathspace's internal reporting system, including account and contact metadata for affected users.
Unauthorized access to Mathspace's Australian internal reporting database began while its self-hosted Metabase instance was vulnerable.
Metabase reportedly disclosed CVE-2026-72898, an unauthenticated SQL-injection flaw in its password-reset API rated CVSS 10.0, and released patches. CISA reportedly added the vulnerability to its Known Exploited Vulnerabilities catalog shortly afterward.
Mathspace took the affected reporting system offline and notified schools, education departments, and cybersecurity authorities. It said it was revising vulnerability-advisory escalation and post-patch verification procedures following the incident.
The ShinyHunters extortion group claimed responsibility for hacking Metabase shortly after patches for CVE-2026-72898 were released. The claim concerns Metabase and does not attribute the Mathspace intrusion to the group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcesecurityweek.com
Open sourcehelpnetsecurity.com
Open sourceteiss.co.uk
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourceblog.mathspace.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.