Mathspace data breach: what happened and what affected users should know
Updated 6 September 2026
On 3 September 2026, we confirmed that unauthorised parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff. Mathspace staff records were also affected. The exposed information included names and email addresses, along with account details described below. Customer passwords, single sign-on (SSO) tokens and other customer authentication credentials were not exposed. We have concluded our investigation into the scope of the exposure and identified the affected accounts and records.
We're truly sorry this happened and are taking steps to prevent similar breaches in the future. Protecting the information entrusted to us by students, families and schools is our responsibility. This page explains what happened, the steps we have taken and how to get help.
We have no evidence so far that the data has been published, distributed, sold or otherwise misused. Identity of the attacker remains unknown as of this writing.
Have you received an email about this incident?
Mathspace began sending data breach notifications to school contacts on 4 September. The incident is real. However, that does not establish that every message referring to it is genuine.
To verify a message or ask about your information, start a new email to data-breach-response@mathspace.co. You can also navigate to Mathspace’s website yourself and use our support channels. Avoid following links or opening attachments in a message you are unsure about.
What happened?
Attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting. The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login.
Metabase published a critical security advisory and patched versions on 6 August 2026. Our existing vulnerability-notification process did not identify and escalate that advisory for action. We updated our instance on 29 August after a later Metabase notice came to our attention.
Our investigation identified unauthorised access dating back to 10 August 2026, Australian Eastern Standard Time. We confirmed that information was downloaded from our Australian reporting database on 27 August.
During our subsequent review of historical access logs, we confirmed on 3 September that unauthorised access had occurred before the update was applied. At the time of updating, we did not complete the additional compromise checks recommended for potentially affected systems.
We are investigating why the initial advisory was not escalated and why those checks were not completed sooner. We are changing both processes as part of our incident response.
Who and what information were affected?
A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected.
The exported information included user ID, username, first name, last name, email address, country, time zone, user type, email-verification status, last-active date, last-login date and date joined. The affected records relate to students, parents or guardians, teachers and Mathspace staff. Not every field was present for every person.
This is more information than names and email addresses alone. Our earlier communications did not describe the account details fully. The user IDs mentioned above are internal Mathspace identifiers, including identifiers associated with student accounts.
No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools.
What should you do?
Names, email addresses and account details can make impersonation attempts more convincing. Someone may use them to send a message that appears to come from Mathspace, your school or another organisation you know.
- Check unexpected messages independently. Be cautious even if a message uses your name or refers accurately to your school or this incident. Use contact details obtained separately from an official website.
- Do not disclose passwords or verification codes in response to a message. Avoid unexpected attachments and requests to sign in through unfamiliar links.
- Use a unique password for each account. Change any passwords you have reused across services.
- Watch for unusual account activity. Pay attention to unexpected password-reset emails or changes to your account details.
- Report suspicious messages or activity to data-breach-response@mathspace.co.
If you are a student and are unsure what to do, ask a parent, guardian or teacher to help.
How can a school confirm its affected numbers and records?
School administrators can contact data-breach-response@mathspace.co to request the number of affected students, school staff, and parents or guardians associated with their school, or details of the affected records. We are coordinating responses to these requests directly with schools and arranging secure sharing where individual records are needed.
Could former or inactive users be affected?
An account does not need to be currently active for information retained in the reporting database to be affected. Leaving a school or stopping use of Mathspace does not, by itself, establish that your information was unaffected.
If you or your school no longer use Mathspace, you can still contact data-breach-response@mathspace.co to confirm whether your information was involved.
Were passwords or authentication credentials affected? Do I need to reset my password?
Customer passwords, single sign-on (SSO) tokens and other customer authentication credentials were not exposed. We are not requiring a Mathspace password reset as a result of this incident.
If you have reused your Mathspace password on another service, change the reused passwords to unique ones. If you notice suspicious account activity, change the affected account’s password and contact us.
What have we done to contain the incident?
On 3 September, after confirming the breach, we:
- Took Metabase, the compromised reporting system, offline.
- Revoked all Metabase API keys.
- Disabled Metabase’s database access accounts in our Australian and US Snowflake environments.
- Changed the passwords for the Metabase Cloud SQL databases.
We also copied the Metabase application database and exported access logs for investigation.
Metabase remains offline. These actions disabled access through the affected reporting system. Recovery work includes addressing unauthorised accounts and sessions and verifying the conditions required before the system can return to service.
Why were schools contacted first, and when will individuals be notified?
We confirmed the breach on 3 September and began notifying school contacts on 4 September. We contacted schools first so that they could coordinate communications with their school communities while we completed our investigation.
Schools informed us that they wanted individuals to be informed as soon as possible, and we have started sending notifications as of 6th of September. This is an earlier date than the one previously communicated to schools.
School administrators can contact data-breach-response@mathspace.co to coordinate communications or request information about their school. Students, parents and guardians can use the same address for questions.
Have regulators and cyber security authorities been notified?
Yes. On 4 September, we reported the incident to:
- The Office of the Australian Information Commissioner (OAIC).
- The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC).
- New Zealand’s Office of the Privacy Commissioner.
- New Zealand’s National Cyber Security Centre.
We also notified Australian state and territory education departments.
Can schools request an incident or forensic report?
Schools seeking an incident or forensic report can contact data-breach-response@mathspace.co with their requirements. We will provide a post-incident update to schools explaining what happened and the changes we are making to prevent a recurrence.
What happens next?
Our remaining work includes notifying affected individuals (we started this on the 6th of September), responding to school requests and completing recovery checks for the reporting system.
Our post-incident review will address how we receive and escalate critical security advisories and how we check for compromise after a vulnerability is disclosed. We will report the resulting changes and their implementation status here.
We will keep this page updated with progress and any changes to the actions affected people should take. For help, contact data-breach-response@mathspace.co.