2026 Mathspace — Metabase reporting system breach; 1,079,819 AU/NZ users
Data compromised
User ID, username, first/last name, email, country, time zone, user type, email-verification status, last-active/login/joined dates (students, parents/guardians, school staff, Mathspace staff); passwords/SSO/auth credentials NOT exposed; no academic/assessment records
Technical writeup
Verified company blog notice (updated September 6, 2026). Mathspace confirmed unauthorized parties accessed a self-hosted Metabase internal reporting system and downloaded information on students, parents/guardians, school staff, and Mathspace staff. Metabase published a critical advisory August 6, 2026; Mathspace patched August 29 after a later notice. Unauthorized access dated to August 10 (AEST); Australian reporting-database download confirmed August 27; scope confirmed September 3. 1,079,819 people in Australia and New Zealand affected. Exported fields included user ID, username, names, email, country, time zone, user type, verification/status dates; no passwords, SSO tokens, API credentials, or academic/assessment records. No evidence of publication/sale at notice time. recordsAffected 1079819; companyConfirmed true.
Root cause
Unpatched Metabase vulnerability on self-hosted internal reporting system