Mathspace has disclosed a data breach affecting 1,079,819 students, teachers, staff, and parents/guardians in Australia and New Zealand after attackers exploited a vulnerable self-hosted Metabase instance. The compromised data included names, usernames, email addresses, and account metadata, and the company warns it may be used for phishing attempts, while confirming no passwords, academic records, or authentication tokens were exposed. #Mathspace #Metabase #ShinyHunters #CVE-2026-72898
Keypoints
- Mathspace says the breach affects over 1 million individuals.
- Attackers exploited a zero-day SQL injection flaw in Metabase.
- The intrusion began on 10 August 2026 and data was downloaded on 27 August.
- Exposed information included names, usernames, email addresses, and login details.
- Mathspace has shut down Metabase access, reset credentials, and notified authorities.
Read More: https://www.securityweek.com/mathspace-data-breach-exposes-over-1-million-people/