Mathspace Data Breach: More Than 1 Million People Affected in Australia and New Zealand

The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system used by the online mathematics education provider. Mathspace says the exposed information included names, email addresses and various account-related details, while passwords, single sign-on credentials and academic records were not exposed.

The incident has drawn significant attention because Mathspace is used by students, parents, teachers and schools, meaning the breach involves personal information connected to a large education user base. As of the latest available update, Mathspace says it has taken the affected reporting system offline, notified relevant authorities and begun contacting people whose information was involved.

What Happened in the Mathspace Data Breach

Mathspace confirmed on September 3, 2026, that unauthorized parties had accessed an internal reporting system and downloaded information associated with students, parents or guardians, school staff and Mathspace employees.

According to Mathspace’s investigation, the attackers gained access through a security vulnerability in a self-hosted installation of Metabase, software the company used for internal reporting. The vulnerability allowed an attacker to obtain administrator access without a legitimate login.

The unauthorized access dates back to August 10, 2026, according to Mathspace. The company confirmed that information was downloaded from its Australian reporting database on August 27.

Mathspace had updated its Metabase installation on August 29 after becoming aware of a later security notice. However, the company subsequently reviewed historical access logs and confirmed on September 3 that unauthorized access had occurred before the update.

The company said its earlier vulnerability-notification process had not identified and escalated the relevant critical security advisory for action. Mathspace is now reviewing how security advisories are received, assessed and escalated.

How Many People Were Affected

Mathspace has identified 1,079,819 affected individuals in Australia and New Zealand.

The affected population includes:

  • Students
  • Parents and guardians
  • Teachers and other school staff
  • Mathspace employees

Mathspace said the investigation has concluded regarding the scope of the affected accounts and records. The company also emphasized that not every affected record contained every category of information.

The incident therefore represents more than a conventional exposure involving a small number of customer accounts. More than one million people are included in the confirmed affected population.

At the same time, Mathspace has said the affected population is limited to users in Australia and New Zealand. This is important for people in the United States who may be searching for information about the incident because there is currently no indication from the company’s disclosure that U.S. users are part of the 1,079,819-person affected group.

What Information Was Exposed

The information downloaded during the incident varied from person to person.

According to Mathspace, potentially exposed information included:

  • User ID
  • Username
  • First name
  • Last name
  • Email address
  • Country
  • Time zone
  • User type
  • Email-verification status
  • Last-active date
  • Last-login date
  • Date the account was created or joined

The company said not every individual had all of these fields in the affected data.

Importantly, Mathspace said the incident did not expose customer passwords, single sign-on tokens or other customer authentication credentials. The company also said academic records, learning activities and results were not included in the stolen information.

That distinction matters because the presence of names and email addresses creates a different risk profile from a breach involving passwords, financial information or detailed academic records.

What Is a Data Breach?

A data breach occurs when unauthorized individuals gain access to information that an organization is responsible for protecting.

A breach can involve many different types of information, including names, email addresses, passwords, financial details, identification information or other personal data. The seriousness of a breach depends partly on what information was accessed, how many people were affected and whether the information was subsequently misused.

In the Mathspace incident, unauthorized parties accessed an internal reporting environment and downloaded personal and account-related information.

A data breach does not necessarily mean that every type of information held by an organization was stolen. In this case, Mathspace has specifically stated that passwords, authentication credentials and academic records were not exposed.

How the Mathspace Breach Happened

The incident was connected to a vulnerability in Mathspace’s self-hosted Metabase installation.

Metabase is used by organizations for business intelligence and reporting. Mathspace used its installation for internal reporting.

Mathspace said Metabase published a critical security advisory and patched versions on August 6, 2026. The company’s existing process did not identify and escalate that advisory for action. Mathspace later updated its installation on August 29.

The company also said that, when the installation was updated, it did not immediately perform the additional compromise checks recommended for systems that may have been exposed to the vulnerability.

A later review of historical logs resulted in the confirmation of unauthorized access on September 3.

The incident demonstrates why applying a software security patch is only one part of responding to a newly discovered vulnerability. Organizations may also need to investigate whether an attacker gained access before the patch was installed.

What Mathspace Has Done Since Discovering the Breach

Mathspace has taken several steps to contain the incident and investigate what happened.

After confirming the breach, the company:

  • Took the compromised Metabase reporting system offline.
  • Revoked Metabase API keys.
  • Disabled Metabase database access accounts in its Australian and U.S. Snowflake environments.
  • Changed passwords for the Metabase Cloud SQL databases.
  • Preserved the Metabase application database and relevant access logs for investigation.

The Metabase system remains offline while Mathspace works through recovery and security checks.

Mathspace is also reviewing its vulnerability-management and incident-response procedures. The company has said its post-incident review will examine why the initial security advisory was not escalated and why additional compromise checks were not completed sooner.

Read also-Manchester Airport Data Breach: Latest Update on the 2026 Cyberattack and Customer Data Exposure

Notifications to Affected People and Schools

Mathspace began notifying school contacts on September 4.

The company initially planned to give schools time to prepare before individual notifications began. Following feedback from schools, Mathspace moved forward with individual notifications, with notifications beginning September 6.

Importantly, not receiving an individual notification immediately does not necessarily mean that someone’s information was unaffected.

Schools can contact Mathspace to request information about the number of affected students, staff members and parents or guardians connected with their school.

Former or inactive users may also be affected because information retained in the reporting database could have been included in the downloaded data. Mathspace has said that people who no longer use the platform can still contact the company to determine whether their information was involved.

What Affected Users Should Watch For

Although Mathspace says passwords and authentication credentials were not exposed, the information involved in the breach could potentially make fraudulent messages more convincing.

Names, email addresses, usernames and other account details can be useful to someone attempting impersonation or phishing.

People who may be affected should therefore be cautious about unexpected communications claiming to come from Mathspace, a school or another familiar organization.

Recommended precautions include:

  • Be cautious with unexpected emails and messages.
  • Avoid opening unexpected attachments.
  • Do not provide passwords or verification codes in response to unsolicited messages.
  • Be careful with unfamiliar login links.
  • Use unique passwords for different online services.
  • Monitor accounts for unusual activity.
  • Independently verify suspicious communications before taking action.

Mathspace has specifically warned users to be cautious even when a message contains accurate personal or school-related information, because information from the incident could potentially make impersonation attempts appear more credible.

Were Passwords or Academic Records Stolen?

Based on Mathspace’s latest disclosure, no.

The company says customer passwords, SSO tokens and other customer authentication credentials were not exposed.

Mathspace has also stated that academic records, learning activities and results were not part of the affected data.

This means the confirmed incident is primarily centered on personal and account-related information rather than students’ mathematical work, grades or assessment records.

Mathspace is not requiring customers to reset their Mathspace passwords because of this particular incident. However, the company recommends changing passwords that have been reused on other services, because password reuse creates a separate security risk.

Authorities Have Been Notified

Mathspace said it reported the incident on September 4 to relevant privacy and cybersecurity authorities in Australia and New Zealand.

Those notifications included Australia’s Office of the Australian Information Commissioner and Australian Cyber Security Centre, as well as New Zealand’s Office of the Privacy Commissioner and National Cyber Security Centre.

Mathspace also notified Australian state and territory education departments.

The company’s regulatory notifications are part of its broader response to an incident involving more than one million people.

Is There Evidence the Stolen Data Has Been Misused?

At the latest confirmed update, Mathspace said there was no evidence that the affected information had been published, distributed, sold or otherwise misused.

The identity of the people responsible for the intrusion has also not been established publicly.

That does not mean the risk has disappeared. The investigation and response process is continuing, and Mathspace is still communicating with affected individuals and schools.

It is therefore important to distinguish between confirmed facts and possible future developments. There is currently no official confirmation that the stolen information has been used for fraud, identity theft or other criminal activity.

Latest Update on the Mathspace Data Breach

The latest reporting on September 7, 2026, confirms that more than one million people were affected by the Mathspace incident. Mathspace has confirmed the affected population as 1,079,819 people in Australia and New Zealand.

The compromised reporting system has been taken offline, and affected individuals are being contacted.

Mathspace has also said that its investigation identified the records and accounts involved. The company continues to work on recovery checks, individual notifications, school requests and improvements to its security processes.

There has been no official confirmation identifying the attackers, and there is no confirmed evidence that the exposed information has been publicly released or misused.

For U.S. readers, the current information is particularly relevant as an example of how vulnerabilities in internal business systems can create risks for large education platforms. However, the confirmed affected population in this incident is Australia and New Zealand rather than the United States.

Why the Incident Matters Beyond Mathspace

The Mathspace breach highlights a broader cybersecurity issue for educational technology providers.

Schools and education platforms routinely handle information about students, parents, teachers and staff. Even information that may appear relatively basic, such as a person’s name and email address, can become valuable when combined with account identifiers and activity information.

The incident also highlights the importance of quickly responding to critical software vulnerabilities.

Mathspace’s disclosure shows that installing a patch after a vulnerability is announced may not be enough if attackers have already gained access. Organizations also need effective processes for identifying potentially compromised systems, reviewing logs and determining whether information was accessed before remediation.

For users, the incident reinforces the importance of recognizing phishing attempts and avoiding password reuse across different services.

What Happens Next

Mathspace’s remaining response includes completing notifications, handling questions from schools and affected individuals, and carrying out recovery checks before restoring the compromised reporting environment.

The company has also committed to reviewing its vulnerability-management processes and how security advisories are escalated internally.

Further information may become available as the response continues. If new findings establish that additional information was involved or that the exposed data was misused, those developments could change the understanding of the incident.

For now, the confirmed facts remain clear: unauthorized parties accessed an internal Mathspace reporting system, information belonging to 1,079,819 people in Australia and New Zealand was downloaded, and Mathspace says passwords, authentication credentials and academic records were not exposed.

Final Thoughts

The Mathspace data breach is a significant education-sector cybersecurity incident because of the number of people affected and the nature of the information involved. While the exposed information did not include passwords or academic records according to Mathspace, names, email addresses and account details can still create privacy and phishing risks.

The company has taken the affected system offline, notified authorities and started contacting affected individuals. There is currently no official confirmation that the stolen information has been published, sold or misused.

Stay updated as Mathspace releases additional verified information, and share your thoughts in the comments if this incident affects you or your school community.

Is Starbucks Open on...

If you're wondering is Starbucks open on Labor Day,...

Does FedEx Deliver on...

If you are waiting for a package or planning...

Cognizant Data Breach: Latest...

The Cognizant data breach remains an important cybersecurity story...

Biftx Expands Cryptocurrency Trading...

Cryptocurrency trading is gaining another platform development story as...

Manchester Airport Data Breach:...

The Manchester Airport data breach has become a major...

What Is a Data...

What is a data breach? It is an incident...