Mathspace, an online maths tutoring platform used in schools across Australia and New Zealand, has confirmed a data breach affecting 1,079,819 people, a figure that includes students, their parents or guardians, school staff, and Mathspace’s own employees. The company disclosed the incident on September 3, 2026, and last updated its public notice on September 6, 2026, saying unauthorised parties gained access to an internal reporting system and downloaded records tied to accounts across its user base.
The breach lands in the middle of a year that has already produced a steady drumbeat of large-scale data incidents, but this one stands out for the population it touches: children and teenagers using a classroom tool, alongside the adults who teach and parent them. According to reporting from Cyber Daily, the incident traces back to an unpatched vulnerability in Mathspace’s self-hosted installation of Metabase, an open-source business intelligence tool many companies use to build internal dashboards.
Mathspace Confirms Data Breach Affecting 1.08 Million Users
Mathspace said in its disclosure notice that unauthorised parties accessed an internal reporting system used by the company and downloaded information tied to students, their parents or guardians, school staff, and Mathspace’s own staff records. The company has not named the attacker or described a motive, and it has not said whether the stolen data has surfaced anywhere since the download occurred.
The scale puts Mathspace among the larger education-sector breaches reported globally this year. Cyber Daily’s report frames the number as “more than 1 million Australians and New Zealanders,” and Mathspace’s own figure of 1,079,819 confirms the company treats every one of those individuals, students, guardians, and staff combined, as affected. Mathspace has said only people located in Australia and New Zealand were affected, which narrows the geographic footprint even as the raw headcount stays large for a company operating primarily in the K-12 education technology space.
Mathspace builds adaptive maths practice software adopted by schools for classroom and homework use, which means its user base skews toward minors, a detail that raises the stakes on any breach involving contact information tied to real identities and account activity.
Timeline: How the Metabase Flaw Went From Advisory to Breach
Mathspace’s investigation found that unauthorised access began on August 10, 2026 (Australian Eastern Standard Time), roughly three and a half weeks before the company went public with the news. The attacker, or attackers, downloaded information from Mathspace’s Australian reporting database on August 27, 2026, according to the company’s own account.
Reporting from The Cyber Express adds detail to the gap between vulnerability and remediation: Metabase issued a critical security advisory and released patches around August 6, 2026, days before Mathspace’s own timeline shows unauthorised access starting. The Cyber Express reports Mathspace applied the Metabase update on August 29, 2026, two days after the data had already been pulled from its database. The company reported the incident to regulators on September 4, 2026, and began notifying affected individuals on September 6, 2026, per that same reporting.
That sequence, a public patch available before exploitation began, followed by a multi-week window before the update was applied internally, is the detail most likely to draw scrutiny from regulators and from the schools that trusted Mathspace with student data. Neither Mathspace nor the outlets covering the story have published a full technical postmortem explaining why the patch took roughly three weeks to reach the affected instance.
What Information Was Exposed in the Mathspace Data Breach
Mathspace said the exposed information included names and email addresses across the affected accounts. The company’s disclosure goes further, listing the specific fields downloaded from its reporting database: user ID, username, first name, last name, email address, country, time zone, user type, email-verification status, last-active date, last-login date, and date joined.
None of that data set includes passwords or payment details, but the combination of names, verified emails, account activity timestamps, and user-type classification (student, parent, or staff) is enough to build a fairly precise profile of who uses Mathspace, how recently, and in what role. That is a meaningful phishing and social-engineering risk even without a single password in the mix, since attackers can use verified, role-tagged email addresses to craft convincing messages aimed at parents or school administrators.
What Mathspace Says Was Not Compromised
Mathspace has been specific about what the breach did not touch. In its public notice, the company stated: “Customer passwords, single sign-on (SSO) tokens and other customer authentication credentials were not exposed.” That distinction matters, since it means attackers cannot use the stolen data set alone to log into student or staff accounts directly.
Mathspace also said no academic or learning data was compromised, meaning grades, assignment history, and problem-solving records tied to individual students appear to have stayed outside the reporting system the attacker accessed. As for whether the stolen records have leaked further, Mathspace’s position, according to its own disclosure, is that “we have no evidence so far that the data has been published, distributed, sold or otherwise misused.” That is a common early-stage claim in breach disclosures and is not the same as confirmation the data stayed private; monitoring services and dark-web marketplaces often surface stolen data sets weeks or months after an initial breach notice.
Root Cause: An Unpatched Self-Hosted Metabase Instance
Cyber Daily’s reporting identifies the entry point as an unpatched vulnerability in Mathspace’s self-hosted installation of Metabase, the same open-source analytics tool that has been tied to other high-profile breaches in past years when left unpatched or misconfigured. Metabase instances are popular precisely because they let non-engineers query production data through dashboards, which also means a compromised instance can expose whatever the connected database holds.
The Cyber Express reports the flaw allowed administrator-level access without legitimate credentials, effectively letting an attacker treat the internal reporting tool as an open door into the underlying data rather than needing to breach the core Mathspace application or its authentication system separately. Self-hosted business intelligence tools sit outside the perimeter that companies usually harden first, since the assumption tends to be that internal dashboards carry lower risk than customer-facing systems. This breach is a reminder that an internal tool connected to a full user database carries exactly the same blast radius as the production system it reports on.
Who Is Affected: Students, Parents, and School Staff
The 1,079,819 figure spans four groups: students who use Mathspace in class or for homework, the parents or guardians linked to those student accounts, school staff who administer Mathspace inside their institutions, and Mathspace’s own employees whose records sat in the same reporting system. Mathspace has not broken down how many people fall into each category, so it is not yet possible to say what share of the total are minors versus adults.
Because Mathspace is deployed at the school level rather than sold directly to individual consumers, many affected students and parents likely have no prior relationship with the company beyond what their school’s IT department set up. That distances the breach from typical consumer-facing incidents where a customer chose to sign up for a service; here, a school’s software choice determined exposure for children and their families.
Mathspace’s Response and Notification Process
Mathspace has published a dedicated breach notice on its company blog and has been notifying affected users directly. The company opened its public statement with an apology, writing: “We’re truly sorry this happened and are taking steps to prevent similar breaches in the future.”
The company’s disclosure lays out what was and was not exposed in plain terms, stating that “the exposed information included names and email addresses, along with account details described below,” a structure aimed at giving affected schools and families a clear checklist rather than vague reassurance. What Mathspace has not yet published, based on the material reviewed for this story, is a named executive quote beyond these company-level statements, or a technical root-cause report detailing exactly how the Metabase instance was exposed to the public internet in the first place.
Mathspace Data Breach at a Glance
| Detail | Figure / Status |
|---|---|
| People affected | 1,079,819 |
| Regions affected | Australia and New Zealand only |
| Breach publicly disclosed | September 3, 2026 |
| Notice last updated | September 6, 2026 |
| Unauthorised access began | August 10, 2026 (AEST) |
| Data downloaded from database | August 27, 2026 |
| Entry point | Unpatched self-hosted Metabase instance |
| Passwords / SSO tokens exposed | No, per Mathspace |
| Academic or learning data exposed | No, per Mathspace |
| Evidence of data being sold or leaked | None reported so far, per Mathspace |
How the Mathspace Breach Compares to Other 2026 Data Breaches
Mathspace’s breach joins a long list of 2026 disclosures spanning healthcare, logistics, toys, and travel infrastructure. The raw headcount puts it below the year’s largest reported incidents but ahead of many mid-tier breaches, and its education-sector focus sets it apart from the healthcare and consumer-retail breaches that have dominated headlines through most of 2026.
| Incident | Sector | People / Records Affected |
|---|---|---|
| Mathspace (Sept 2026) | Education technology | 1,079,819 people |
| McKesson / ShinyHunters claim | Healthcare distribution | 284 million records claimed |
| Manchester Airports Group | Aviation infrastructure | 8.7 million records |
| French hospital (CNIL-fined) | Healthcare | 727,000 records |
| Hasbro | Consumer goods / employer | 436 employees (SSNs) |
| Dropbox (via Lenovo ID) | Cloud storage | 5,000 accounts |
What separates Mathspace from most entries on that list is the age profile of the people involved. A breach touching 436 employees or 5,000 cloud-storage accounts involves working adults who can act on their own behalf. A breach touching a school platform means guardians and IT administrators have to act on behalf of children who may not understand what a data breach notice even means.
Historical Context: EdTech’s Recurring Security Problem
Education technology vendors have struggled with security maturity for years, largely because school procurement cycles reward feature sets and pricing over security audits. Districts and school systems typically lack the staff to run vendor security assessments at the depth that a bank or hospital system would demand, and smaller edtech vendors often run lean engineering teams without dedicated security staff watching internal tools like analytics dashboards.
Self-hosted business intelligence software has been a recurring weak point industry-wide, not just at Mathspace. Metabase and similar tools sit adjacent to production databases by design, and a misconfigured or unpatched instance can turn what was meant to be an internal reporting convenience into a single point of failure for an entire user base. Mathspace’s incident fits a pattern security researchers have flagged repeatedly: internal tooling gets less scrutiny than customer-facing login pages, even though it frequently has broader data access.
Regulatory Exposure Under Australia’s Notifiable Data Breaches Scheme
Because the affected population sits in Australia and New Zealand, Mathspace’s obligations run through Australia’s Notifiable Data Breaches scheme, administered by the Office of the Australian Information Commissioner, which requires organisations to report eligible data breaches and notify affected individuals when the breach is likely to result in serious harm. New Zealand runs a parallel notification requirement under its own Privacy Act.
A breach touching over a million people, a large share of them minors, is the kind of incident regulators tend to examine closely, particularly the question of why a publicly available Metabase patch sat unapplied for roughly three weeks while the vulnerable instance remained internet-reachable. Whether Mathspace faces a formal investigation, a fine, or simply a compliance review is not yet confirmed, and the company has not disclosed any regulatory findings beyond confirming it notified authorities.
Market and Industry Impact for EdTech Vendors
Mathspace is a privately held company, so there is no public stock reaction to measure the way there might be for a listed vendor. The more immediate market effect will likely show up in school procurement conversations: district IT leads and school boards evaluating edtech tools now have a fresh, concrete example to raise when vendors pitch analytics-heavy platforms, and “do you self-host Metabase or similar BI tools, and how do you patch them” is likely to become a standard vendor-security question in coming renewal cycles.
Competing adaptive-learning platforms may use the incident as a selling point, emphasizing managed or vendor-hosted analytics stacks over self-hosted internal tools. Cyber insurance underwriters covering edtech clients are also likely to start asking pointed questions about internal BI tooling exposure, an area that has historically received far less underwriting attention than customer-facing authentication systems.
What Affected Families and Schools Should Do Now
Mathspace says passwords and login credentials were not exposed, so there is no indication accounts themselves are at immediate risk of takeover through this specific breach. The practical risk sits with the exposed names, verified email addresses, and account metadata, which attackers could use for targeted phishing aimed at parents, school staff, or students.
- Treat any unexpected email referencing Mathspace, your school, or your child’s account with caution, and verify sender addresses before clicking links.
- Do not reuse your Mathspace password anywhere else, and consider rotating it as a precaution even though Mathspace says credentials were not exposed.
- School IT administrators should confirm with Mathspace directly what specific accounts under their institution were affected rather than relying on the general public notice.
- Parents can use a monitoring service such as Have I Been Pwned to check whether an email address tied to their child’s account has appeared in this or other breaches.
- Watch for phishing attempts that reference specific, accurate account details, since attackers with real names and activity timestamps can craft more convincing messages than generic scams.
What’s Next: Predictions for the Mathspace Fallout
A few outcomes look likely in the weeks ahead, based on how similar breaches have played out this year:
- Expect Australian and New Zealand privacy regulators to open at least a preliminary review given the size of the affected population and the presence of minors’ data, even if no fine follows quickly.
- Expect school districts and education departments that use Mathspace to request a direct security briefing or updated data-processing agreement before the next school term begins.
- Expect at least one class-action or consumer-protection inquiry to be floated in Australian media, following the pattern set by other 2026 breach settlements this year, though nothing has been filed as of this writing.
- Expect Mathspace to publish a more detailed technical postmortem in the coming weeks, since companies facing this level of scrutiny typically follow an initial disclosure with a fuller root-cause report once the investigation closes.
- Expect rival edtech vendors to quietly audit their own self-hosted analytics tools, since Metabase and comparable BI platforms are widely used across the sector and this incident puts a spotlight on a previously under-scrutinized attack surface.
Frequently Asked Questions
What happened in the Mathspace data breach?
Unauthorised parties accessed an internal reporting system at Mathspace and downloaded records covering 1,079,819 students, parents or guardians, school staff, and Mathspace employees in Australia and New Zealand.
When did the Mathspace breach happen?
Mathspace says unauthorised access began August 10, 2026, and data was downloaded from its Australian reporting database on August 27, 2026. The company disclosed the breach publicly on September 3, 2026.
Were passwords exposed in the Mathspace breach?
No. Mathspace says customer passwords, single sign-on tokens, and other authentication credentials were not exposed.
Was student academic data compromised?
Mathspace says no academic or learning data, such as grades or assignment history, was compromised in this breach.
How did the attacker get in?
According to Cyber Daily and The Cyber Express, the attacker exploited an unpatched vulnerability in Mathspace’s self-hosted installation of Metabase, an internal business intelligence and reporting tool.
Who is affected by the Mathspace breach?
Students, their parents or guardians, school staff, and Mathspace’s own employees in Australia and New Zealand. Mathspace has not broken down the total by category.
Has the stolen Mathspace data been leaked or sold?
Mathspace says it has no evidence so far that the data has been published, distributed, sold, or otherwise misused, though this status can change as investigations continue.
What should I do if my child’s school uses Mathspace?
Watch for phishing emails referencing your child’s account, avoid reusing your Mathspace password elsewhere, and check with your school’s IT department for confirmation of whether your specific account was affected.




