INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Mathspace Discloses Data Breach Affecting Over 1 Million Users Worldwide

| 2026-09-07 13:05 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On August 27, attackers gained access to Mathspace's internal reporting system and downloaded information on students, their parents or guardians, and school staff from its Australian reporting database. The breach affected nearly 1 million people in Australia and New Zealand, specifically targeting students and school staff from these countries. Only individuals with data stored in the compromised systems were impacted, totaling around 1,079,819 people combined. Attackers exploited a security vulnerability to obtain administrator access without legitimate login credentials, allowing them to download sensitive information such as personal details and email addresses. The breach was discovered on September 3, but attackers had gained access to the system on August 10.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA NORTH_AMERICA educationeducation logisticslogistics
Incident Timeline
‎2026/08/08
ShinyHunters claimed responsibility for breaching Metabase, exploiting a SQL injection zero-day vulnerability to steal data from customer instances.
threat_actor ShinyHunters
organisation BleepingComputer
organisation Metabase SQL
‎August 10
Threat actors gained access to Mathspace's systems on August 10, allowing them to download data from the Australian reporting database later that month.
target_region Australia
organisation Mathspace
‎August 11
ShinyHunters added Metabase to its dark web leak site on August 11.
threat_actor ShinyHunters
‎August 13
Threat actors used Trezor to reveal that attackers stole data of nearly 14,000 customers after hacking ShipMonk.
industry Logistics
organisation Trezor
victims 14,000 customers
‎August 27
Threat actors gained access to Mathspace's Australian reporting database on August 27 and downloaded data, which was confirmed stolen on September 3.
target_region Australia
organisation Mathspace
‎3 September 2026
Threat actors accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff.
‎September 3
Threat actors gained access to Mathspace's systems on August 10 and downloaded data from the Australian reporting database on August 27, which was confirmed stolen on September 3.
target_region Australia
organisation Mathspace
‎September 2026
Threat actors, linked to ShinyHunters, exploited a zero-day flaw in Oracle PeopleSoft to target over 1 million people primarily from Australia and New Zealand.
organisation ShipMonk
threat_actor ShinyHunters
organisation Salesloft Drift
victims 100 enterprise victims
organisation SSO
organisation API
organisation Savoy
organisation Framework
organisation The Blue Report 2026
‎2026/09/07
Unknown attackers gained access to Mathspace's Metabase internal reporting system, stealing personal information from over 1 million students, staff, and parents.
organisation Metabase
organisation Mathspace CTO Alvin Savoy
Tactical Metrics
Metrics
victims
14,000
Customers
Metrics
victims
100
Enterprise Victims
Intelligence Sources
BleepingComputer 2026-09-07