The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Mathspace's official blog, ABC News, 7NEWS, Cyber Daily and other outlets confirm the Sept 3 disclosure of a Metabase breach affecting 1,079,819 AU/NZ users.

Sourcing
4independent sources

via BleepingComputer

BleepingComputer · track record
75Stories
100%Verified
630d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/Mathspace breach exposes data of 1,079,819 users
VERIFIEDBy Xavier Rivera· ·2 min read

Mathspace breach exposes data of 1,079,819 users

Mathspace disclosed that attackers stole personal data belonging to 1,079,819 students, staff, and parents or guardians in Australia and New Zealand after breaching its Metabase system. The incident is the latest in a campaign exploiting a Metabase zero-day vulnerability used by multiple companies.

Source:BleepingComputer
Post
Mathspace breach exposes data of 1,079,819 users
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

Mathspace disclosed a breach exposing names, emails, and account details of 1,079,819 users in Australia and New Zealand. Attackers exploited a Metabase vulnerability in August to access the internal reporting system and download data. The incident is part of a wider campaign targeting Metabase instances. Affected users now face elevated phishing and account takeover risks.

Mathspace has disclosed a data breach that exposed personal information belonging to more than 1 million students, staff, and parents or guardians.

Attackers accessed the company's Metabase internal reporting system. The breach was confirmed on September 3, 2026 after unauthorized parties gained access on August 10 and downloaded data from the Australian reporting database on August 27. Mathspace CTO Alvin Savoy stated that attackers exploited a security vulnerability in the self-hosted Metabase installation to obtain administrator access without a legitimate login.
Only users in Australia and New Zealand were impacted.

The company took the affected system offline after discovery. Savoy said the exposed data included names and email addresses along with user ID, username, country, timezone, user type, verification status, and last active, login, and joined dates. No academic records, learning activities, results, assessment records, passwords, authentication tokens, SSO credentials, or API credentials were exposed.
https://x.com/AlvieriD/status/2087147709278912658

Only users in Australia and New Zealand were impacted. A total of 1,079,819 people were affected, according to Savoy. The company, founded in Sydney in 2010, is used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom. In 2023 it reported 3,432 schools in Australia and 3,557 abroad.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

Savoy noted that while records did not directly link user accounts to their schools, for schools with identifiable email domains this may be possible. The company has notified affected individuals, authorities, and education departments. There is no evidence the data has been published, sold, or misused.
The breach is part of a wider campaign targeting Metabase instances.

Mathspace warns of potential phishing and account takeover risks. Savoy advised affected students and school staff to watch for suspicious activity such as changes to account details or password-reset messages. He urged users to change passwords if they reuse them elsewhere and apologized for the incident, accepting full responsibility.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
The breach is part of a wider campaign targeting Metabase instances. Over the last month, threat actors have exploited a critical Metabase SQL injection zero-day vulnerability to breach multiple companies worldwide. ShinyHunters has claimed responsibility for several of these incidents, including those affecting laptop maker Framework, online form-building platform Tally, and shipping provider ShipMonk, which saw customer data stolen from nearly 81,000 individuals. Mathspace has not attributed the attack to a specific group.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · The Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
data-breachcybersecurityeducation-tech
More fromBleepingComputer
  • OpenAI Begins Gradual Release of Astra to ChatGPT Plus Subscribers

    Tech · 12h
  • OpenAI Acknowledges Partial Outage Hitting ChatGPT Work

    Tech · 6d
  • Carhartt data breach exposes 12.9 million accounts

    Tech · 11d
More inTech
  • iPhone Handoff to share one number across two devices in iOS 27

    Tech · 9h
  • iPhone 18 Pro Leaks, BYD’s 10,000 Chargers, DLSS 5 Mod

    Tech · 9h
  • OpenAI Begins Gradual Release of Astra to ChatGPT Plus Subscribers

    Tech · 12h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Free forever.

From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN TECH

iPhone Handoff to share one number across two devices in iOS 27

iPhone Handoff will let users switch between two iPhones sharing one number when iOS 27 launches later this month. The feature supports pairing a main device with a companion and requires carrier support, with code referencing T-Mobile US and Telekom.de.

iPhone 18 Pro Leaks, BYD’s 10,000 Chargers, DLSS 5 Mod

A busy week featured iPhone 18 Pro dummy units ahead of the September 9 keynote, BYD’s deployment of 10,000 ultra-fast chargers since March 5, and tinkerers applying AI tools including DLSS 5 and Claude to everyday devices. The recap also highlights the growing threat of SIM swapping scams that can empty bank accounts through intercepted authentication codes.

OpenAI Begins Gradual Release of Astra to ChatGPT Plus Subscribers

OpenAI is gradually releasing its flagship model Astra to $20 ChatGPT Plus subscribers, with initial availability inside the Work section. No information has been provided on possible access for free users.