Home / Blog / Mathspace Data Breach Exposes Over 1 Million People
Tech News

Mathspace Data Breach Exposes Over 1 Million People

Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance. Mathspace Data Breach Exposes Over 1.

By Dillip Chowdary • Sep 26, 2026 • Source: SecurityWeek

Mathspace Data Breach Exposes Over 1 Million People

What broke in Mathspace Data Breach Exposes Over 1 Million

SecurityWeek reports: Mathspace Data Breach Exposes Over 1 Million People. Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance. The post Mathspace Data Breach Exposes Over 1 Million People appeared first on SecurityWeek .

Mathspace, an online mathematics program for students, has disclosed a data breach that impacts over 1 million individuals. The incident, it says, was discovered last week, roughly three weeks after hackers compromised its self-hosted Metabase instance using a known vulnerability.

Who is exposed by Mathspace Data Breach Exposes Over 1 Million

Mathspace Data Breach Exposes Over 1 Million People
Illustration · Pexels

The security defect, tracked as CVE-2026-72898 (CVSS score of 10/10) and described as an SQL injection issue, was patched on August 6, after it had been exploited in the wild as a zero-day. Shortly after the patches were released, the notorious extortion group ShinyHunters claimed responsibility for hacking Metabase.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

What to do now about Mathspace Data Breach Exposes Over 1 Million

Mathspace failed to escalate Metabase’s critical advisory to prioritize patching and upgraded its instance on August 29, more than two weeks after hackers hit it. See the full write-up from SecurityWeek via the source link for quotes and complete context.

“Our investigation identified unauthorised access dating back to 10 August 2026, Australian Eastern Standard Time. Furthermore, Mathspace did not complete the compromise checks Metabase had recommended, and did not identify the intrusion upon applying the update.

How the Mathspace Data Breach Exposes Over 1 Million issue works

“We are investigating why the initial advisory was not escalated and why those checks were not completed sooner. We are changing both processes as part of our incident response,” the online platform says.

What is still unknown about Mathspace Data Breach Exposes Over 1 Million

Mathspace has taken its Metabase instance offline, revoked API keys, disabled the database access accounts, changed passwords, and exported the logs for investigation. See the full write-up from SecurityWeek via the source link for quotes and complete context.

Developer Action Items

  • ☐ Inventory whether Mathspace Data Breach Exposes runs in prod, CI, staging, or on laptops before you debate severity.
  • ☐ Pull the vendor advisory for CVE-2026-72898 and patch from that page — not from a social recap.
  • ☐ If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
  • ☐ Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
  • ☐ Treat unexpected emails that mention Mathspace Data Breach Exposes (shipping, invoices, password resets) as phishing until verified.
Dillip Chowdary

Author

Dillip Chowdary

Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.

Related on Tech Bytes

Advertisement

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →