INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Mathspace Discloses Data Breach Affecting Over 1 Million Users Worldwide
| 2026-09-07 13:05 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On August 27, attackers gained access to Mathspace's internal reporting system and downloaded information on students, their parents or guardians, and school staff from its Australian reporting database. The breach affected nearly 1 million people in Australia and New Zealand, specifically targeting students and school staff from these countries. Only individuals with data stored in the compromised systems were impacted, totaling around 1,079,819 people combined. Attackers exploited a security vulnerability to obtain administrator access without legitimate login credentials, allowing them to download sensitive information such as personal details and email addresses. The breach was discovered on September 3, but attackers had gained access to the system on August 10.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
educationeducation
logisticslogistics
Incident Timeline
2026/08/08
ShinyHunters claimed responsibility for breaching Metabase, exploiting a SQL injection zero-day vulnerability to steal data from customer instances.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Metabase breaches claimed by ShinyHunters
This breach adds to a string of other incidents impacting the Metabase instances of multiple other companies worldwide over the last month,
As
BleepingComputer previously reported
, threat actors exploited a critical Metabase SQL injection zero-day vulnerability to breach customer instances and steal data after gaining administrator access.
organisation
BleepingComputer
Metabase breaches claimed by ShinyHunters
This breach adds to a string of other incidents impacting the Metabase instances of multiple other companies worldwide over the last month,
As
BleepingComputer previously reported
, threat actors exploited a critical Metabase SQL injection zero-day vulnerability to breach customer instances and steal data after gaining administrator access.
organisation
Metabase SQL
Metabase breaches claimed by ShinyHunters
This breach adds to a string of other incidents impacting the Metabase instances of multiple other companies worldwide over the last month,
As
BleepingComputer previously reported
, threat actors exploited a critical Metabase SQL injection zero-day vulnerability to breach customer instances and steal data after gaining administrator access.
August 10
Threat actors gained access to Mathspace's systems on August 10, allowing them to download data from the Australian reporting database later that month.
Click on any entity below to view its context and source!
target_region
Australia
"
While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27.
organisation
Mathspace
"
While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27.
August 11
ShinyHunters added Metabase to its dark web leak site on August 11.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
ShinyHunters also
added Metabase
to its dark web leak site on August 11.
August 13
Threat actors used Trezor to reveal that attackers stole data of nearly 14,000 customers after hacking ShipMonk.
Click on any entity below to view its context and source!
industry
Logistics
Trezor
revealed on August 13
that attackers stole the data of nearly 14,000 customers after hacking its shipping and logistics provider, ShipMonk.
organisation
Trezor
Trezor
revealed on August 13
that attackers stole the data of nearly 14,000 customers after hacking its shipping and logistics provider, ShipMonk.
victims
14,000 customers
Trezor
revealed on August 13
that attackers stole the data of nearly 14,000 customers after hacking its shipping and logistics provider, ShipMonk.
August 27
Threat actors gained access to Mathspace's Australian reporting database on August 27 and downloaded data, which was confirmed stolen on September 3.
Click on any entity below to view its context and source!
target_region
Australia
"
While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27.
organisation
Mathspace
"
While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27.
3 September 2026
Threat actors accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff.
September 3
Threat actors gained access to Mathspace's systems on August 10 and downloaded data from the Australian reporting database on August 27, which was confirmed stolen on September 3.
Click on any entity below to view its context and source!
target_region
Australia
"
While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27.
organisation
Mathspace
"
While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27.
September 2026
Threat actors, linked to ShinyHunters, exploited a zero-day flaw in Oracle PeopleSoft to target over 1 million people primarily from Australia and New Zealand.
Click on any entity below to view its context and source!
organisation
ShipMonk
Although Trezor has yet to attribute the attack to a specific threat actor or hacking group, BleepingComputer has learned that ShipMonk has received extortion emails from the ShinyHunters extortion gang.
threat_actor
ShinyHunters
Although Trezor has yet to attribute the attack to a specific threat actor or hacking group, BleepingComputer has learned that ShipMonk has received extortion emails from the ShinyHunters extortion gang.
Previously, ShinyHunters has been linked to breaches at
more than a dozen Snowflake customers
,
Salesloft Drift
and
Salesforce Aura
campaigns targeting
hundreds of Salesforce customers
, and
over 100 enterprise victims
following data-theft attacks
that exploited an Oracle PeopleSoft zero-day flaw
.
organisation
Salesloft Drift
Previously, ShinyHunters has been linked to breaches at
more than a dozen Snowflake customers
,
Salesloft Drift
and
Salesforce Aura
campaigns targeting
hundreds of Salesforce customers
, and
over 100 enterprise victims
following data-theft attacks
that exploited an Oracle PeopleSoft zero-day flaw
.
victims
100 enterprise victims
Previously, ShinyHunters has been linked to breaches at
more than a dozen Snowflake customers
,
Salesloft Drift
and
Salesforce Aura
campaigns targeting
hundreds of Salesforce customers
, and
over 100 enterprise victims
following data-theft attacks
that exploited an Oracle PeopleSoft zero-day flaw
.
organisation
SSO
"No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed.
organisation
API
"No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed.
organisation
Savoy
"
Savoy also warned affected students and school staff that attackers may target them using the stolen data, and advised them to watch for suspicious account-related activity, such as changes to account details and password-reset messages.
organisation
Framework
The list of affected companies in this campaign also includes laptop maker Framework and online form-building platform Tally, which have also disclosed data breaches after their Metabase instances were hijacked.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
2026/09/07
Unknown attackers gained access to Mathspace's Metabase internal reporting system, stealing personal information from over 1 million students, staff, and parents.
Click on any entity below to view its context and source!
organisation
Metabase
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system.
organisation
Mathspace CTO Alvin Savoy
In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attackers gained access to the company's systems and stole personal information belonging to school staff and students, as well as their parents and guardians.
Tactical Metrics
Metrics
victims
14,000
Customers
Click for context!
Trezor
revealed on August 13
that attackers stole the data of nearly 14,000 customers after hacking its shipping and logistics provider, ShipMonk.
Metrics
victims
100
Enterprise Victims
Previously, ShinyHunters has been linked to breaches at
more than a dozen Snowflake customers
,
Salesloft Drift
and
Salesforce Aura
campaigns targeting
hundreds of Salesforce customers
, and
over 100 enterprise victims
following data-theft attacks
that exploited an Oracle PeopleSoft zero-day flaw
.
Intelligence Sources
BleepingComputer
2026-09-07
Mathspace discloses data breach affecting over 1 million people
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:59
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
Trezor
entity
9x
timeline
Temporal Reference
2010
date
4x
target region
Target Country
Australia
country
2x
tactic
Cyber Operation Type
Data Breach
tactic
2x
general metric
People
1,000,000
people
Contextual Telemetry
Context Block
7 METRICS
general metric
United Kingdom
3,432
united kingdom
industry
Targeted Sector
Logistics
sector
victims
Customers
14,000
customers
threat actor
APT Group
ShinyHunters
actor
victims
Enterprise Victims
100
enterprise victims
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.