Mathspace Data Breach Exposes Information of Over 1 Million Users
Attackers accessed Metabase reporting system; personal and educational data compromised

Key Takeaways
- Mathspace confirmed a data breach impacting over 1 million users.
- The breach involved unauthorized access to the Metabase internal reporting system.
- The specific data exfiltrated and initial access vector have not been publicly detailed.
- The organization is implementing security measures to secure the Metabase instance.
- Internal reporting and analytics platforms can present significant risk if compromised.
Quick answers
- What happened?
- Online maths learning platform Mathspace disclosed a data breach affecting more than 1 million students, staff, and parents. Attackers gained unauthorized access to the organization's Metabase internal reporting system and exfiltrated data. The full scope of categories of information accessed and the initial intrusion method remain under investigation.
- Which products are affected?
- Metabase
- What should defenders do?
- Mathspace is applying security measures to the Metabase instance. Affected individuals are advised to monitor accounts for unusual activity. Organizations should ensure internal BI tools are properly segmented and access-controlled.
Mathspace, an online mathematics learning platform, notified affected individuals over the weekend that a breach of its Metabase internal reporting system compromised data belonging to more than 1 million students, staff, and parents. According to the disclosure, attackers obtained unauthorized access to the Metabase instance and exfiltrated information stored within the system. The company has not specified the exact data categories accessed, nor the method by which the initial breach occurred. Mathspace stated it is applying additional security measures to the Metabase environment. The incident highlights the risks associated with internal business intelligence tools when exposed to unauthorized access. Further details regarding the threat actor, precise data exfiltrated, and remediation steps are pending.
Security Details
Unauthorized access to Mathspace's Metabase internal reporting system resulted in exfiltration of student, staff, and parent data. The exact data categories and initial access method are under investigation.
Affected products
Metabase
Mitigation
Mathspace is applying security measures to the Metabase instance. Affected individuals are advised to monitor accounts for unusual activity. Organizations should ensure internal BI tools are properly segmented and access-controlled.
Sources
BleepingComputer
Mathspace discloses data breach affecting over 1 million people
Sep 7, 2026 · 13:05
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

French Tax Administration Data Breach Exposed Hundreds of Thousands of Records via Stolen Staff Credentials
An unauthorized access incident at France's Direction Générale des Finances Publiques (DGPP) compromised tax data belonging to hundreds of thousands of taxpayers and businesses between June and July 2026. According to a report published by France's national cybersecurity agency ANSSI on 29 September 2026, the attacker used stolen staff passwords to gain entry. The agency stated the attack was 'not sophisticated' and went undetected for seven weeks due to weak security controls. ANSSI noted that neither the tax administration nor the agency itself observed data exfiltration, though the breach resulted in unauthorized access to sensitive fiscal information.



