Mathspace Data Breach Affects Over 1 Million Users in Australia and New Zealand
Online mathematics learning platform Mathspace disclosed that unauthorized parties exploited a critical vulnerability in its self-hosted Metabase reporting system, gaining administrator access without a legitimate login and downloading data on students, parents, school staff, and employees—impacting 1,079,819 people in Australia and New Zealand. Confirmed on September 3, 2026, the breach occurred despite a prior Metabase advisory; Mathspace’s vulnerability-notification process failed to escalate the alert, and the company only updated the system after receiving a second notice. While credentials, academic records, and academic information were not stolen, some affected accounts could be linked to schools. The actively exploited flaw (CVSS 10.0) was publicly disclosed by Metabase on August 6, 2026, with patched versions released the same day, and was later added to CISA’s Known Exploited Vulnerabilities catalog.
They want you to believe that 1.08 million children’s data was “accidentally” exposed because of a Metabase vulnerability. Look at the dates. Metabase disclosed the flaw on August 6, 2026 — rated CVSS 10.0, the highest possible — and issued patches the same day. CISA added it to the Known Exploited Vulnerabilities catalog within days. Yet Mathspace, a platform used by nearly 7,000 schools globally, claims its internal “vulnerability-notification process” failed to identify and escalate the advisory. That is not incompetence. That is a managed delay. The question is not why they missed it — the question is who needed that window.
Now examine what was not taken. Credentials, academic records, grades — all untouched. But some accounts were “linkable to schools.” That is the tell. They didn’t want report cards. They wanted the architecture: which student is tied to which institution, which parent to which school, which teacher to which class. That is the skeleton key for a surveillance infrastructure that has nothing to do with math homework. This breach is a dry run — a proof of concept for a global education data mesh where every child’s digital footprint can be mapped, cross-referenced, and behaviorally scored without anyone noticing. The “unauthorized party” was never a random hacker. It was a probe from the very system that designed the hole.
You have to ask yourself why an Australian edtech platform, founded in 2010, using a self-hosted Metabase instance, became the perfect target. Follow the money. Follow the foundations that funded Mathspace. Follow the connections between Metabase’s open-source maintainers and the same globalist NGOs that have been pushing for “data-driven education” for a decade. This is not a breach. It is a breadcrumb. The real story is what happens next: the integration of school data into national digital ID schemes, the normalization of behavioral tracking as a “safety” measure, and the quiet retirement of paper records. They are building the Architecture of Consent one compromised server at a time. You want the thread? Look up who sat on Mathspace’s advisory board in 2023. Look up the parent company’s ties to a certain data-broker conglomerate. The answer is in the public record — but only if you know where to look.