A devastating cyberattack on Mathspace has compromised the personal data of more than one million students, staff, and parents in Australia and New Zealand, after hackers exploited a critical flaw in the Metabase reporting system.
More than one million individuals-students, teachers, and parents-across Australia and New Zealand have had their personal data stolen in a sweeping cyberattack on Mathspace, the online maths learning platform trusted by thousands of schools. The breach, confirmed by Mathspace CTO Alvin Savoy, is the latest and largest in a series of attacks exploiting a critical vulnerability in Metabase, the internal reporting tool used by the company.
The attackers did not waste time. Gaining access on August 10, they spent just over two weeks inside Mathspace's systems before extracting the entire Australian reporting database on August 27. The breach was only confirmed on September 3, leaving a significant window for data exfiltration. The compromised information includes names and contact details of students, staff, and their guardians-1,079,819 people in total-though Mathspace insists that passwords, academic records, and authentication credentials were not exposed.
Il punto di rottura: la falla Metabase
The root cause is as technical as it is damning. Attackers exploited a security flaw in Mathspace's self-hosted Metabase instance, granting themselves administrator privileges without any legitimate login. This vulnerability has become a favorite target for cybercriminals in recent months, with similar attacks hitting companies worldwide. The notorious ShinyHunters group has already claimed responsibility for several Metabase-related breaches, and their extortion tactics have been documented in other high-profile incidents, including the ShipMonk and Trezor cases.
Mathspace's CTO, Alvin Savoy, was blunt in his assessment: "Attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting. The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login." The company's transparency about the timeline and scope of the breach is notable, but it does little to soften the blow for affected schools and families.
Impatto reale su scuole e famiglie
While Mathspace claims that no academic results or passwords were leaked, the exposed data is far from trivial. For schools using identifiable email domains, attackers may be able to link accounts to specific institutions, raising the risk of targeted phishing or social engineering attacks. Savoy has urged vigilance, warning users to monitor for suspicious account activity and unexpected password reset requests.
The breach is confined to Australia and New Zealand, sparing Mathspace's users in the United States and United Kingdom for now. Yet the scale is staggering: 3,432 Australian schools and 3,557 international institutions rely on Mathspace, according to 2023 figures. The incident echoes the recent reported earlier breach at RingCentral, also attributed to ShinyHunters, which exposed 1.6 million accounts and highlighted the persistent threat posed by sophisticated cyber extortion groups.
Una catena di attacchi e la risposta del settore
This Mathspace breach is not an isolated event. In the past month alone, Metabase vulnerabilities have been weaponized against a growing list of companies, including Framework and Tally, with attackers leveraging zero-day exploits to seize administrator access and siphon sensitive data. The ShinyHunters group, already infamous for attacks on Snowflake customers and Salesforce-related campaigns, has added Metabase to its dark web leak arsenal, intensifying pressure on organizations to patch or migrate away from vulnerable systems.
Mathspace's rapid disclosure and detailed incident timeline set a higher bar for transparency, but the underlying issue remains: educational platforms are now prime targets for cybercriminals, and the sector's reliance on third-party tools like Metabase is a glaring weak point. Until vendors and institutions alike prioritize robust security practices and timely patching, schools and families will continue to pay the price for systemic negligence. The lesson is clear-no amount of digital innovation can compensate for basic security failures, and the cost of complacency is measured in the privacy of millions.