Mathspace, an online learning platform used by schools in Australia and New Zealand, has confirmed a cyberattack that affected more than 1 million students, parents, teachers, and staff.
The company said attackers gained access to an internal reporting system and copied user information. In total, 1,079,819 people were affected.
The incident was linked to a critical vulnerability in Metabase, the reporting software used by Mathspace.
How the Attack Happened
The attackers exploited CVE-2026-72898, a critical SQL injection vulnerability in Metabase.
The flaw could be exploited remotely without a username or password and was rated 10.0 out of 10 in severity. Security agencies also warned that the vulnerability was being actively exploited.
Mathspace said its vulnerability-alert process failed to identify and escalate the warning quickly enough. The company’s Metabase system remained exposed while attackers gained access and later removed data from the database.
The timeline shows the gap:
- August 6: Metabase released a security fix
- August 10: Unauthorized access began
- August 27: Data was taken from the system
- August 29: Mathspace updated Metabase
- September 3: The company confirmed the earlier intrusion
What Information Was Exposed?
The stolen information varied between users but could include names, email addresses, usernames, account IDs, country, time zone, and account activity details.
Mathspace said that passwords, password hashes, SSO tokens, API credentials, grades, assessment results, and learning activity were not exposed.
The company has not identified the attacker and said it currently has no evidence that the stolen information has been published or misused.
Mathspace Takes Action
Mathspace has taken the affected reporting system offline and reviewed historical logs to understand the incident. It has also notified schools, education authorities, and relevant cybersecurity agencies.
The company is now strengthening its process for handling vulnerability alerts and checking systems after security updates are applied.
For affected users, the incident is also a reminder to be cautious with unexpected emails or password-reset messages. Avoid clicking suspicious links, use unique passwords, and monitor accounts for unusual activity.
The breach highlights an important lesson for organizations: installing a security patch is only one part of vulnerability management. Teams also need to quickly identify critical alerts, apply fixes, and verify that vulnerable systems were not already compromised.