discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Mathspace discloses data breach affecting over 1 million people

Mathspace, a math learning platform, has disclosed a data breach affecting over 1 million users, including students, staff, and parents.

By Sergiu Gatlan·Sep 7·bleepingcomputer.com·2 min read

Intelligence analysis by Qwen 2.5 (3B)

Mathspace discloses data breach affecting over 1 million people
Image: bleepingcomputer.com

Mathspace, a math learning platform, has disclosed a data breach affecting over 1 million users, including students, staff, and parents. The breach occurred after attackers gained access to the company's internal reporting system.

Why it matters

This data breach could potentially compromise sensitive personal and academic information, including student records and parent contact details.

Mathspace, a place where kids learn math, had a problem where bad people got into their computer system and took some personal information from students, teachers, and parents. They said it only happened in Australia and New Zealand, but it's still a problem because the bad people might be able to connect the information to the school.

Analysis

{"

Metabase Breach Details":"Mathspace disclosed that attackers gained access to an internal reporting system used by the company and downloaded information on students, their parents or guardians, and school staff. The breach occurred on August 10 and data was downloaded from the Australian reporting database on August 27.","

Impact of the Breach":"Only students and school staff from Australia and New Zealand were affected. No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools.","

Previous Breaches":"This breach is part of a string of incidents impacting Metabase instances of multiple other companies worldwide. Other companies affected include Trezor, Tally, and Framework. ShinyHunters, the threat actor behind these breaches, has also been linked to other data theft attacks.","

Prevention and Detection":"Once attackers have valid credentials, only 37% of their actions are blocked. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. The report highlights the importance of prevention techniques and the challenges of detecting and blocking initial access."}

Key points

  • Mathspace disclosed a data breach affecting over 1 million users, including students, staff, and parents.
  • Only students and school staff from Australia and New Zealand were affected.
  • No academic records, learning activities, results, assessment records, passwords, authentication tokens, SSO credentials, or API credentials were exposed.
  • The exposed data did not include records linking user accounts to their schools.
  • The breach occurred after attackers gained access to the company's internal reporting system.
  • This breach is part of a string of incidents impacting Metabase instances of multiple other companies worldwide.
The Upside

The company is taking steps to secure their systems and warn affected users, which can help prevent further misuse of the stolen information.

The Downside

The breach could lead to identity theft or other misuse of the stolen information, especially if the bad people can connect the information to the school.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritydata-breachmathspacemetabaseeducation

Author

Sergiu Gatlan

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 7, 2026

Source

bleepingcomputer.com

Share

Topics

securitydata-breachmathspacemetabaseeducation

Related

More from this desk

Sep 7·bleepingcomputer.com

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Magento zero-day vulnerability exploited to deploy Linux backdoor. Adobe Enterprise Support working on fix.

Sep 7·thehackernews.com

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters disclose a data theft and extortion threat targeting Microsoft 365 and SaaS users through fake IT calls and proxy sign-ins.

Sep 7·bleepingcomputer.com

BigBear Microsoft 365 phishing service bypasses MFA at 258 organizations

Phishing-as-a-service framework BigBear 2.0 bypassed MFA at 258 organizations, stealing over 5,000 Microsoft 365 credentials.

Sep 7·thehackernews.com

Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

This week, attackers used a QR code workaround to bypass email image blocking, and a trusted software source delivered code that stole credentials. MikroTik RouterOS flaws were exploited, and Magento and Adobe Commerce were compromised with an unpatched zero-day.