Mathspace, an online mathematics learning platform used in schools across Australia and New Zealand, has confirmed a data breach affecting 1,079,819 people, according to the company’s own incident disclosure and reporting from ABC News. The figure covers students, parents and guardians, teachers, and Mathspace staff, and the Mathspace data breach is now one of the largest single-vendor education data exposures reported in the Asia-Pacific region this year. Nine.com.au, Qazinform and The Cyber Express also picked up the story on September 7, 2026, all citing the same headline number Mathspace published in its own breach notice.
Unlike many recent education-sector incidents, this one did not start with a phishing email or a stolen laptop. Mathspace says attackers got in by exploiting a known vulnerability in Metabase, an internal analytics and reporting tool the company runs on its own servers. No passwords, single sign-on tokens, or academic records were taken, but the scale and the underlying cause, an unpatched, publicly disclosed flaw, are already drawing comparisons to earlier education-technology breaches such as the PowerSchool incidents of 2024 and 2025.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
Timeline: How the Mathspace Data Breach Unfolded
Piecing together Mathspace’s own account with reporting from ABC News and Nine.com.au, the incident stretched across nearly a month before it became public. ABC News reported that the breach occurred between August 10 and August 27, 2026, a window during which a security update for the affected system had not yet been applied. Mathspace says it confirmed on September 3, 2026 that unauthorised parties had accessed an internal reporting system and downloaded information tied to students, parents, guardians, and school staff. The company then notified regulators the following day and published its own incident explainer shortly after, with the post later updated on September 6, 2026.
| Date | Event |
|---|---|
| August 6, 2026 | Metabase publishes a critical security advisory for a vulnerability affecting self-hosted installations, according to cybersecurity researchers tracking the incident. |
| August 10–27, 2026 | Window during which attackers accessed Mathspace’s internal reporting system, per ABC News and Nine.com.au. |
| September 3, 2026 | Mathspace confirms unauthorised access and data download, according to its own incident blog. |
| September 4, 2026 | Mathspace notifies Australian and New Zealand regulators, according to reporting on the incident. |
| September 5–6, 2026 | Mathspace publishes and updates its public breach notice. |
| September 7, 2026 | ABC News, Nine.com.au, The Cyber Express, Qazinform, BleepingComputer and 7NEWS report the story publicly. |
That gap between the intrusion window and public confirmation, roughly five weeks, is one of the details likely to draw scrutiny from privacy regulators in both countries. Mathspace has not disclosed exactly how it detected the unauthorised access, and none of the outlets covering the Mathspace data breach have attributed the discovery to an outside security researcher or a dark-web listing. As far as public reporting shows, Mathspace identified the intrusion through its own internal review process.
Who Was Affected: Students, Parents, Teachers and Staff
Mathspace’s breach notice states plainly: “A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined.” The company also confirmed the geographic scope was limited, saying “Only people in Australia and New Zealand were affected.” That detail matters for two reasons. First, it means Mathspace’s user base outside those two markets, if any, was untouched by this particular incident. Second, it puts the exposure squarely under Australian and New Zealand privacy law rather than a more fragmented, multi-jurisdiction response.
Mathspace has not broken the 1,079,819 figure down by category, so it is not possible to say precisely how many of those affected are children under 18, how many are parents, and how many are teaching staff. ABC News and Nine.com.au both describe the same undifferentiated total, and neither outlet reports a per-group split. Given that Mathspace’s core product is a K-12 maths platform used directly by students in classrooms, it is reasonable to assume students make up a large share of the total, but that inference is not something Mathspace or the outlets covering the story have confirmed with a number.
What Data Was Exposed, and What Wasn’t
The specifics of what was and wasn’t taken are the clearest part of Mathspace’s disclosure, and they are the reason the company has been able to frame this as a lower-severity incident than a typical credential-stuffing breach. According to Mathspace’s blog and consistent with ABC News and Nine.com.au reporting, the exposed fields were account and contact metadata rather than anything that would let an attacker log into a Mathspace account directly.
| Data Category | Status |
|---|---|
| User ID, username | Exposed |
| First and last name | Exposed |
| Email address | Exposed |
| Country, time zone | Exposed |
| User type (student, parent/guardian, teacher, staff) | Exposed |
| Email verification status, last active date, last login date, date joined | Exposed |
| Passwords, password hashes | Not exposed |
| Single sign-on (SSO) tokens, authentication credentials | Not exposed |
| API credentials | Not exposed |
| Academic records, learning activity, assessment results | Not exposed |
| Direct records linking accounts to specific schools | Not exposed |
In its own words, Mathspace says: “Customer passwords, single sign-on (SSO) tokens and other customer authentication credentials were not exposed.” The company also says the compromised data did not include direct records linking individual accounts to their schools, though it acknowledges that where a school uses a distinctive email domain, an outside party could potentially infer a school affiliation by looking at the domain in an exposed email address. That is a meaningful caveat: even without a labelled “school” field, a leaked list of names, emails and account-activity timestamps tied to a known school domain is still useful information for a targeted phishing campaign aimed at that school community.
Inside the Vulnerability Behind the Mathspace Data Breach
Mathspace attributes the intrusion to a security vulnerability in its self-hosted installation of Metabase, the open-source business intelligence and reporting tool many companies run internally to build dashboards on top of their own databases. According to Mathspace’s account, the flaw let attackers obtain administrator-level access to the reporting system without going through a legitimate login. Cybersecurity researchers tracking the incident have linked the exploited flaw to a vulnerability publicly disclosed on August 6, 2026, roughly four days before Mathspace’s own stated intrusion window began.
That sequencing, a public vulnerability disclosure followed within days by exploitation against an unpatched instance, is a familiar pattern in enterprise security. It’s the same dynamic that has driven a wave of 2026 incidents where organisations running self-hosted versions of widely used software found themselves exposed in the narrow window between a vendor’s advisory and their own patch cycle. Mathspace has not published a detailed post-mortem on why its own Metabase instance had not been updated by the time the exploit window opened, and no source reviewed for this article quotes Mathspace directly on that point.
Mathspace’s Response and Regulatory Notifications
Mathspace’s public messaging has focused on two things: limiting the scope of what was taken, and reassuring users there is no evidence of downstream misuse. The company states directly: “We have no evidence so far that the data has been published, distributed, sold or otherwise misused.” That statement, taken at face value, means Mathspace has not seen the dataset appear on a criminal marketplace or leak site as of its most recent update, though it stops short of guaranteeing that outcome going forward.
On the regulatory side, reporting on the incident indicates Mathspace notified Australia’s Office of the Australian Information Commissioner and the Australian Cyber Security Centre, along with New Zealand’s Office of the Privacy Commissioner and its National Cyber Security Centre, in the days immediately following its September 3 internal confirmation. Both countries operate mandatory data breach notification regimes, Australia under the Notifiable Data Breaches scheme overseen by the OAIC, and New Zealand under the Privacy Act 2020, enforced by the Office of the Privacy Commissioner. A breach of this size, touching over a million individuals, is likely to draw formal review from at least one of those bodies, though neither regulator has issued a public statement specific to Mathspace as of this writing.
Media Reaction: ABC News, Nine.com.au and the Wider Coverage
The story broke into mainstream Australian and New Zealand media on September 7, 2026. ABC News framed the breach around the headline figure and the account-metadata nature of the exposure, noting the absence of academic records or authentication data among the leaked fields. Nine.com.au ran a parallel account with the same numbers and timeline, describing the August 10-27 intrusion window in detail. The Cyber Express and Qazinform both picked up the story the same day, repeating the 1,079,819 figure that originated from Mathspace’s own disclosure. The incident was also covered by BleepingComputer and 7NEWS, both of which cited the same total confirmed by Mathspace rather than independently sourced figures.
What stands out across this coverage is how uniform the reporting has been. Every outlet is working from the same primary source, Mathspace’s own incident blog, rather than independent investigation or leaked documents. That is not unusual for a same-day breaking story, but it also means the full picture, including exactly how the intrusion was detected and whether any data has since surfaced elsewhere, will likely take weeks to fill in as regulators and independent researchers dig further.
Why EdTech Platforms Keep Becoming Breach Targets
Education technology vendors sit on an unusually attractive dataset: large volumes of personal information tied to minors, aggregated across many schools and districts, often behind a single login system shared by an entire institution. That concentration is exactly what makes a single vendor breach so consequential, one compromised system can expose data tied to hundreds of schools in one event, rather than requiring an attacker to break into each school individually.
The Mathspace incident also illustrates a second recurring theme in 2026 breach disclosures: the attack surface is increasingly the internal tooling companies use to run their own business, not just the customer-facing product. Metabase, in this case, was not the maths platform students and teachers log into. It was an internal analytics tool Mathspace’s own staff used to build reports. That distinction matters because internal tools often receive less security scrutiny and slower patch cycles than the primary product, even though they can hold direct database access to the same underlying customer data.
Historical Context: Mathspace Compared to Other EdTech Breaches
The Mathspace data breach lands in a sector that has already seen major disclosures in North America. PowerSchool, a widely used student information system in the United States and Canada, disclosed a significant breach in late 2024 that was reported extensively through 2025 and drew scrutiny for exposing more sensitive categories of student data in some affected districts, including identifiers beyond names and email addresses. By contrast, Mathspace’s exposure, at least based on what the company has disclosed, is narrower in the type of data taken: contact and account-activity metadata rather than the more sensitive identifiers or academic history involved in some prior education-sector incidents.
The attack vectors also differ in a telling way. Reporting on prior PowerSchool-related incidents has tied them to compromised credentials and extortion-style tactics associated with cybercriminal groups. The Mathspace breach, as described by the company itself, traces back to a known, patchable software vulnerability in a self-hosted internal tool rather than a stolen login or a named ransomware operator. No threat actor or ransomware group has been publicly attributed to the Mathspace incident, and Mathspace states the identity of the attacker remains unknown.
Mathspace vs Other Learning Platforms: A Security Comparison
| Factor | Mathspace (2026) | PowerSchool-related incidents (2024-2025, general reporting) |
|---|---|---|
| Geographic scope | Australia and New Zealand only | Primarily United States and Canada |
| Root cause | Unpatched vulnerability in a self-hosted internal analytics tool | Compromised credentials, per prior reporting on related incidents |
| Passwords/credentials exposed | No, per Mathspace’s own statement | Varied by incident and district, per prior reporting |
| Academic records exposed | No, per Mathspace’s own statement | Reported as exposed in some cases, per prior coverage |
| Attacker identified | Unknown, per Mathspace | Linked to extortion activity in prior reporting |
| Evidence of data being sold or leaked | None found so far, per Mathspace | Varied by incident |
This comparison is necessarily qualitative rather than a precise numbers match, since Mathspace and the PowerSchool-related incidents were disclosed under different regulatory regimes with different reporting requirements. What it does show is a pattern across the edtech sector: even when the specific data categories or attack vectors differ, the underlying exposure, a single vendor holding centralized personal data on students and staff across many institutions, keeps producing large-scale breach events year after year.
Market and Industry Impact
Mathspace is a privately held company, so there is no public stock reaction to track the way there might be for a listed cybersecurity vendor or a breached public company. The more immediate market impact is likely to play out in two places: cyber insurance underwriting and school procurement decisions. Coverage of the incident has already framed it as a case study in patch-management obligations under cyber insurance policies, since the exploited flaw had a public vendor advisory available roughly four days before the reported intrusion window opened. Insurers increasingly scrutinize how quickly a policyholder applies critical patches, and a breach traced directly to a delayed update on a high-severity, publicly disclosed vulnerability is the kind of fact pattern that can affect renewal terms.
For schools and education departments, the more practical impact is procurement scrutiny. Australian and New Zealand education authorities that contract with edtech vendors typically require some form of data-handling assurance, and a breach affecting over a million user accounts across two countries is likely to prompt renewed questions from IT and procurement teams at school systems that use Mathspace or similar platforms, regardless of whether they were directly named as affected.
What Mathspace and the Data Show
Because this is a fast-moving, single-source story, the clearest evidence available comes directly from Mathspace’s own incident disclosure rather than independent commentary. Four statements from that disclosure capture the company’s position on scale, geography, and exposure:
“On 3 September 2026, we confirmed that unauthorised parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff.”
Mathspace, official incident disclosure (source)
“A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined.”
Mathspace, official incident disclosure (source)
“Customer passwords, single sign-on (SSO) tokens and other customer authentication credentials were not exposed.”
Mathspace, official incident disclosure (source)
“We have no evidence so far that the data has been published, distributed, sold or otherwise misused.”
Mathspace, official incident disclosure (source)
Read together, these four statements form the backbone of every news report on the Mathspace data breach published so far, including coverage from ABC News, Nine.com.au, The Cyber Express and Qazinform. No independent security researcher or regulator has yet published a conflicting account of scope or cause.
What Affected Users and Schools Should Do Now
Mathspace’s own guidance, echoed across the coverage of the incident, centers on phishing vigilance rather than password resets, since credentials themselves were not part of the exposed data. That said, basic account hygiene remains sound advice any time a service you use confirms a breach, even a limited one.
- Treat unexpected emails referencing Mathspace, your school, or “urgent account verification” with suspicion, particularly ones asking for a password or personal details.
- Go directly to Mathspace’s website or your school’s official communication channel to verify any message claiming to be about the breach, rather than clicking links in the email itself.
- Enable multi-factor authentication on your Mathspace account and other key accounts where it is available, even though Mathspace says login credentials were not exposed in this incident.
- If you reuse the same password across multiple sites, change it, since exposed names and email addresses are frequently used to target the same person on other, less secure services.
- School IT administrators should confirm with Mathspace whether their specific school’s email domain appeared among the exposed accounts, since that could make a school community a more likely phishing target even without a direct “school” field in the leaked data.
What Happens Next: 5 Predictions
With the story less than a day old at the time of writing, most of what happens next is analysis rather than confirmed fact. Based on how similar-scale breaches have played out in Australia and New Zealand’s regulatory environment, a few outcomes look likely.
- Regulatory review will likely take months, not weeks. Given the scale, over a million individuals across two jurisdictions, both the OAIC and New Zealand’s Office of the Privacy Commissioner are likely to open some form of formal assessment, a process that historically takes months to conclude.
- Expect follow-up reporting on the patch timeline. The gap between the public vulnerability advisory and Mathspace’s stated intrusion window is the kind of detail investigative outlets and security researchers tend to dig into further once the initial news cycle settles.
- Phishing attempts referencing Mathspace are likely to spike in the near term. Large batches of verified, real names and email addresses tied to a known institution are valuable for follow-on scam campaigns, regardless of whether passwords were included.
- Cyber insurance terms for edtech vendors running self-hosted BI and analytics tools may tighten. Insurers watching this incident are likely to ask policyholders more pointed questions about patch cadence on internal tooling, not just customer-facing systems.
- Other schools and districts using Mathspace, or similar platforms, will likely request updated data-handling assurances. A breach of this size tends to trigger a wave of procurement-level questions across an entire sector, not just at the company directly involved.
The Bigger Picture for EdTech Security
The Mathspace data breach is a reminder that a company’s security posture is only as strong as its least-scrutinized internal system. Mathspace’s core maths platform was not the point of failure here, an internal reporting tool was. That is a pattern worth watching across the wider edtech sector: as vendors add more internal dashboards, analytics pipelines and business intelligence tools to manage growing user bases, each of those tools becomes a potential entry point with direct access to the same underlying customer data the main product protects. For an industry that handles data on minors at a scale few other sectors match, the margin for that kind of oversight keeps shrinking.
Frequently Asked Questions
How many people were affected by the Mathspace data breach?
Mathspace confirmed 1,079,819 people were affected, a figure that includes students, parents and guardians, teachers, and Mathspace staff across Australia and New Zealand.
Were passwords exposed in the Mathspace breach?
No. Mathspace states that customer passwords, password hashes, single sign-on tokens, and other authentication credentials were not part of the exposed data.
What data was actually exposed in the Mathspace data breach?
Exposed fields included user IDs, usernames, first and last names, email addresses, country, time zone, user type, email verification status, last active date, last login date, and date joined, according to Mathspace’s own disclosure.
How did the Mathspace breach happen?
Mathspace says attackers exploited a security vulnerability in its self-hosted installation of Metabase, an internal reporting and analytics tool, gaining administrator-level access without a legitimate login.
When did the Mathspace breach occur and when was it disclosed?
According to ABC News, the intrusion occurred between August 10 and August 27, 2026. Mathspace confirmed the breach internally on September 3, 2026, and the story became widely reported on September 7, 2026.
Has Mathspace identified who was behind the attack?
No. Mathspace says the identity of the attacker remains unknown, and no ransomware group or threat actor has been publicly attributed to the incident.
Is stolen Mathspace data being sold or shared online?
Mathspace says it has no evidence so far that the data has been published, distributed, sold, or otherwise misused, though the company has not ruled out that possibility going forward.
What should Mathspace users do after the breach?
Users should watch for phishing emails referencing Mathspace or their school, avoid clicking links in unsolicited messages, enable multi-factor authentication where possible, and change reused passwords on other accounts, even though Mathspace login credentials themselves were not exposed.


