Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Mathspace Data Breach Exposes 1 Million Users’ Personal Info
September 7, 2026
Hackers Hide Credential-Stealing Phishing in Google Services
September 7, 2026
OpenAI Pledges $1 Billion for Critical Infrastructure AI Cybersecurity Tools
September 7, 2026
Home/CyberSecurity News/Mathspace Data Breach Exposes 1 Million Users’ Personal Info
CyberSecurity News

Mathspace Data Breach Exposes 1 Million Users’ Personal Info

Key Takeaways Mathspace, an online mathematics learning platform, experienced a data breach impacting over one million users. Attackers exploited CVE-2026-72898, a critical SQL injection...

Jennifer sherman
Jennifer sherman
September 7, 2026 3 Min Read
2 0

Key Takeaways

  • Mathspace, an online mathematics learning platform, experienced a data breach impacting over one million users.
  • Attackers exploited CVE-2026-72898, a critical SQL injection vulnerability in the company’s internal Metabase reporting software.
  • The breach exposed personal information including names, email addresses, and account details for students, parents, guardians, and school staff in Australia and New Zealand.
  • Passwords, academic records, and sensitive learning activity data were not compromised.
  • Mathspace failed to patch the critical vulnerability in a timely manner, allowing attackers to exfiltrate data.

Mathspace Breach Exposes Over 1 Million Users Due to Unpatched Critical Flaw

Mathspace, a prominent online learning platform for mathematics, has confirmed a significant data breach affecting more than one million users across Australia and New Zealand. The incident stemmed from the exploitation of a critical vulnerability in the company’s internal reporting software, leading to unauthorized access and exfiltration of personal data belonging to students, parents, guardians, and school personnel.

Table Of Content

  • Key Takeaways
  • Mathspace Breach Exposes Over 1 Million Users Due to Unpatched Critical Flaw
  • Exploitation of CVE-2026-72898
  • Delayed Patching and Detected Intrusion
  • Compromised Data and Remedial Actions
  • What You Should Do

On September 3, 2026, the Sydney-based educational technology firm disclosed that malicious actors had infiltrated an internal reporting system. This compromise resulted in the download of records associated with students, their families, educators, and even Mathspace’s own employees. In total, 1,079,819 individuals were impacted, marking one of the largest education-sector breaches in the region this year.

Exploitation of CVE-2026-72898

According to Mathspace’s disclosure, the breach was facilitated by a security flaw in their self-hosted Metabase installation, an open-source business intelligence tool utilized for internal reporting. The vulnerability, identified as CVE-2026-72898, is an unauthenticated SQL injection. This critical flaw was present in Metabase’s password-reset API endpoint, allowing attackers to execute arbitrary SQL commands and gain administrator privileges without requiring valid credentials.

Metabase publicly disclosed this severe vulnerability on August 6, 2026, assigning it the highest possible CVSS score of 10.0 and releasing patches on the same day. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) promptly added the flaw to its Known Exploited Vulnerabilities catalog, highlighting the rapid weaponization of this vulnerability by threat actors against internet-facing systems.

Delayed Patching and Detected Intrusion

Despite the immediate public disclosure and availability of a patch, Mathspace failed to address the vulnerability in a timely manner. The company admitted that its “existing vulnerability-notification process did not identify and escalate that advisory for action.” Consequently, unauthorized access to its Australian reporting database commenced on August 10, merely four days after the fix was released. Data exfiltration then occurred on August 27.

Mathspace only updated its Metabase instance on August 29, following a separate, later notification that brought the issue to their attention. Crucially, the company initially omitted the additional compromise checks recommended by Metabase for systems that had remained unpatched during the exploitation window. This oversight meant the initial intrusion went undetected until a subsequent review of historical access logs on September 3 confirmed the unauthorized access prior to the patch application.

Compromised Data and Remedial Actions

The exfiltrated records included user IDs, usernames, first and last names, email addresses, country, time zone, account type, email verification status, last active date, last login date, and account creation date. The specific fields present varied for each affected individual. Mathspace has confirmed that no passwords, password hashes, single sign-on tokens, API credentials, academic records, assessment results, or learning activity data were compromised. The company also noted that while the stolen data did not directly link accounts to specific schools, such associations could be inferred for institutions using identifiable email domains.

Mathspace stated that there is “no evidence so far” that the stolen data has been published, sold, or otherwise misused, and the identity of the attacker remains unknown. In response to the breach, Mathspace has taken the affected reporting system offline, notified relevant schools, education departments, and cybersecurity authorities. The company is also revising its advisory-escalation and post-patch verification processes to bolster its defenses against future incidents.

What You Should Do

  • Exercise extreme caution with any unexpected emails or communications that claim to be from Mathspace or your school, especially if they mention the data breach. Verify legitimacy through official channels before clicking links.
  • Avoid reusing passwords across different online services. If you have used the same password for Mathspace and other accounts, change it immediately for all affected services.
  • Monitor your online accounts for any unusual password-reset requests or suspicious login activity.
  • Be vigilant for potential phishing attempts that may leverage the exposed personal information to gain further access to your accounts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVECybersecurityExploitPatchSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Hackers Hide Credential-Stealing Phishing in Google Services

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
ConnectWise Patches Critical ScreenConnect Vulnerability CVE-2024-46805
September 7, 2026
New Linux Botnet Masquerades as Kernel Process to Launch DDoS Attacks
September 7, 2026
LG Smart TVs Vulnerable to Network Scanning and Audio Logging in Standby
September 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us