Mathspace discloses data breach affecting over 1 million people
Mathspace disclosed a Metabase breach exposing data of 1,079,819 students, parents, and staff in Australia and New Zealand.
Mathspace confirmed attackers exploited a vulnerability in its self-hosted Metabase reporting system, gaining administrator access without legitimate login and downloading data on over 1 million people (1,079,819 total) in Australia and New Zealand. Access began August 10, data was downloaded August 27, and the theft was confirmed September 3, 2026. No credentials, academic records, or school-account links were exposed, but affected individuals are warned of targeted phishing. The incident joins a broader campaign against Metabase instances, including Trezor's provider ShipMonk, Framework, and Tally, linked to ShinyHunters via extortion emails and leak-site listings.
Mathspace breach exposes data on over a million students and parents
Mathspace confirmed attackers exploited an unpatched Metabase SQL injection flaw to steal personal data of 1,079,819 students, parents, and staff in Australia and New Zealand.
Attackers accessed Mathspace's self-hosted Metabase reporting system without legitimate login, with unauthorized access dating back to 10 August 2026 and data downloaded on 27 August. Exposed data includes names, usernames, email addresses, country, and account metadata; no passwords, academic records, SSO tokens, or API credentials were taken. Framework, Tally, and Kilo Code disclosed similar breaches via the same Metabase SQL injection flaw in August 2026.
Mathspace Breach Impacts More Than 1 Million Users in Australia, NZ
Mathspace confirmed a breach affecting 1,079,819 people in Australia and New Zealand after unauthorized parties downloaded user data from an internal system.
Mathspace confirmed on September 3, 2026 that a breach affected 1,079,819 people in Australia and New Zealand. Unauthorized parties accessed an internal reporting system and downloaded user information. Affected records involve students, parents or guardians, teachers, and Mathspace staff, including names and other data.
Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports
Manchester Airports Group breach exposed email addresses, phone numbers and vehicle registrations of about 8.7 million customers across three UK airports.
Manchester Airports Group (MAG) disclosed that an unauthorized third party accessed customer data for roughly 8.7 million people across Manchester, London Stansted and East Midlands airports. Exposed data covers car park, lounge and fast-track bookings and Wi-Fi sign-ups, including email addresses, phone numbers, vehicle registration numbers and postcodes; no bank or payment details were stored and no flight operations were disrupted. MAG learned of the incident on August 25 after attackers breached the system over the weekend, contained it, hired external security experts and suspended its Manage My Booking service as a precaution. The breach lands during peak summer travel and adds pressure on UK infrastructure operators after recent incidents at Jaguar Land Rover, M&S, Harrods, Co-op and a UK power plant.