The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Mathspace's official blog, ABC News, 7NEWS, Cyber Daily and other outlets confirm the Sept 3 disclosure of a Metabase breach affecting 1,079,819 AU/NZ users.

Sourcing
4independent sources

via BleepingComputer

BleepingComputer · track record
78Stories
100%Verified
230d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/Mathspace breach exposes data of 1,079,819 users
VERIFIEDBy Xavier Rivera· ·2 min read

Mathspace breach exposes data of 1,079,819 users

Mathspace disclosed that attackers stole personal data belonging to 1,079,819 students, staff, and parents or guardians in Australia and New Zealand after breaching its Metabase system. The incident is the latest in a campaign exploiting a Metabase zero-day vulnerability used by multiple companies.

Source:BleepingComputer
Post
Mathspace breach exposes data of 1,079,819 users
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

Mathspace disclosed a breach exposing names, emails, and account details of 1,079,819 users in Australia and New Zealand. Attackers exploited a Metabase vulnerability in August to access the internal reporting system and download data. The incident is part of a wider campaign targeting Metabase instances. Affected users now face elevated phishing and account takeover risks.

Mathspace has disclosed a data breach that exposed personal information belonging to more than 1 million students, staff, and parents or guardians.

Attackers accessed the company's Metabase internal reporting system. The breach was confirmed on September 3, 2026 after unauthorized parties gained access on August 10 and downloaded data from the Australian reporting database on August 27. Mathspace CTO Alvin Savoy stated that attackers exploited a security vulnerability in the self-hosted Metabase installation to obtain administrator access without a legitimate login.
Only users in Australia and New Zealand were impacted.

The company took the affected system offline after discovery. Savoy said the exposed data included names and email addresses along with user ID, username, country, timezone, user type, verification status, and last active, login, and joined dates. No academic records, learning activities, results, assessment records, passwords, authentication tokens, SSO credentials, or API credentials were exposed.
https://x.com/AlvieriD/status/2087147709278912658

Only users in Australia and New Zealand were impacted. A total of 1,079,819 people were affected, according to Savoy. The company, founded in Sydney in 2010, is used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom. In 2023 it reported 3,432 schools in Australia and 3,557 abroad.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

Savoy noted that while records did not directly link user accounts to their schools, for schools with identifiable email domains this may be possible. The company has notified affected individuals, authorities, and education departments. There is no evidence the data has been published, sold, or misused.
The breach is part of a wider campaign targeting Metabase instances.

Mathspace warns of potential phishing and account takeover risks. Savoy advised affected students and school staff to watch for suspicious activity such as changes to account details or password-reset messages. He urged users to change passwords if they reuse them elsewhere and apologized for the incident, accepting full responsibility.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
The breach is part of a wider campaign targeting Metabase instances. Over the last month, threat actors have exploited a critical Metabase SQL injection zero-day vulnerability to breach multiple companies worldwide. ShinyHunters has claimed responsibility for several of these incidents, including those affecting laptop maker Framework, online form-building platform Tally, and shipping provider ShipMonk, which saw customer data stolen from nearly 81,000 individuals. Mathspace has not attributed the attack to a specific group.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
data-breachcybersecurityeducation-tech
More fromBleepingComputer
  • Denmark CPR breach exposes data of 8.8 million people

    Tech · 3d
  • Microsoft Rolls Out Windows 11 2026 Update as Small Enablement Package

    Tech · 9d
  • OpenAI confirms GPT-6 Astra reaches Critical cybersecurity threshold

    Tech · 1mo
More inTech
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 8h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 11h
  • Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Tech · 11h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    FBI Probes Sale of 153M Drivers License Scans on Dark Web

    The FBI is investigating the dark web sale of scans from more than 153 million US and Canadian drivers licenses obtained via an ongoing breach at a Louisiana identity verification company. The incident underscores the lasting danger of stolen physical identity documents that cannot be reset like passwords and the growing scale of cyber-enabled identity theft.

  • Tech· 

    Carhartt data breach exposes 12.9 million accounts

    ShinyHunters published data from 12.9 million genuine Carhartt accounts after the apparel company refused a $3.3 million ransom. The breach, which also exposed records for more than 15,000 employees, originated from Carhartt's Databricks analytics platform.

  • Tech· 

    ShinyHunters Extortion Gang Leaks Data from 1.6 Million RingCentral Accounts

    ShinyHunters obtained and later leaked personal data belonging to 1.6 million RingCentral accounts after a July breach. The incident touched only a limited portion of the cloud communications provider’s customers and left core services untouched.

  • Tech· 

    KDDI breach hits email platform used by five Japanese ISPs

    KDDI disclosed that attackers breached an email platform used by five Japanese ISPs, exposing email addresses of 12,233,087 people and passwords of 7,616,173 others via a zero-day vulnerability first exploited on May 16. The company is forcing password changes and has deployed new detection tools after notifying regulators, with no confirmed secondary damage reported.

  • Tech· 

    Moody Bible Institute breach leaves 2.3M accounts needing salvation, says cyber expert

    ShinyHunters has published files on more than 2.3 million individuals linked to Moody Bible Institute following the college's June disclosure of a cyberattack. The release, which includes personal details and donor paperwork, underscores the crew's pattern of exposing data from targets that decline its ransom requests.