Mathspace Data Breach Exposes Over 1 Million People
Mathspace disclosed a data breach affecting over 1.07 million students, teachers, staff, and parents/guardians in Australia and New Zealand Hackers exploited CVE-2026-72898, a critical SQL injection vulnerability (CVSS 10/10) in a self-hosted Metabase instance, which had been patched as a zero-day on August 6 Mathspace failed to prioritize the critical advisory, delaying its patch until August 29, and did not complete recommended compromise checks after the update The extortion group ShinyHunter
Analysis
TL;DR
- Mathspace disclosed a data breach affecting over 1.07 million students, teachers, staff, and parents/guardians in Australia and New Zealand
- Hackers exploited CVE-2026-72898, a critical SQL injection vulnerability (CVSS 10/10) in a self-hosted Metabase instance, which had been patched as a zero-day on August 6
- Mathspace failed to prioritize the critical advisory, delaying its patch until August 29, and did not complete recommended compromise checks after the update
- The extortion group ShinyHunters claimed responsibility for the attack, which occurred between August 10 and August 27, 2026
- Stolen data included names, user IDs, usernames, email addresses, and login activity; no passwords, academic records, or school-linked data were exposed
Why It Matters
This incident highlights the critical importance of rapid vulnerability response and proper incident response procedures, especially for organizations relying on self-hosted business intelligence tools. It serves as a cautionary example of how delayed patching and incomplete compromise assessments can extend the window of exposure, directly impacting hundreds of thousands of users.
Technical Details
- Vulnerability exploited: CVE-2026-72898, an SQL injection flaw in Metabase with a CVSS score of 10/10, patched on August 6 after being actively exploited in the wild as a zero-day
- Attack vector: Hackers compromised Mathspace's self-hosted Metabase instance, gaining unauthorized access to its Australian reporting database
- Data exfiltrated: Names, user IDs, usernames, email addresses, email verification status, time zone, country, date joined, and last login/active dates for 1,079,819 individuals
- Remediation actions taken: Mathspace took the Metabase instance offline, revoked API keys, disabled database access accounts, changed passwords, and exported logs for forensic investigation
- Data not exposed: No academic records, learning activities, assessment results, password hashes, authentication tokens, SSO credentials, or school-linking records were compromised
Industry Insight
- Organizations must establish clear escalation protocols for critical security advisories; the two-week delay between the Metabase patch and Mathspace's response allowed active exploitation to continue unchecked
- Applying a vulnerability patch is insufficient—comprehensive compromise checks and forensic investigation must be completed immediately to detect and contain any existing breaches
- Self-hosted BI and analytics tools represent a significant attack surface; organizations should prioritize asset inventory, vulnerability management SLAs, and continuous monitoring for all externally facing or data-sensitive internal systems
Disclaimer: The above content is generated by AI and is for reference only.