Mathspace data breach exposes personal information of more than 1 million users

Mathspace has disclosed a major data breach affecting 1,079,819 users across Australia and New Zealand. The exposed individuals include students, parents, guardians, teachers, and company employees.

Mathspace data breach exposes personal information of more than 1 million usersMathspace data breach exposes personal information of more than 1 million users

Attackers exploited CVE-2026-72898, a critical SQL injection vulnerability in Metabase that allowed unauthenticated access to the internal reporting system. The attackers accessed and exfiltrated personal information including names, email addresses, usernames, account IDs, and activity timestamps.

Mathspace has taken the affected system offline, investigated the incident, and notified relevant authorities. The company said passwords, SSO tokens, academic records, grades, and learning activity data were not exposed. The incident highlights the importance of vulnerability management, endpoint protection, timely patching, and continuous security monitoring.

NPAV Endpoint Security - Helps protect endpoints against malware, suspicious activity, and unauthorized access following security breaches.