More than 1 million users affected in Mathspace data breach across Australia and New Zealand

Posted Mon 7 Sep 2026 at 4:53pmMon 7 Sep 2026 at 4:53pmMon 7 Sep 2026 at 4:53pm

In short:

More than a million people, including students, school staff, and parents have been affected by a data breach across Australia and New Zealand.

Learning provider Mathspace says “unauthorised parties had accessed an internal reporting system” and the exposed information included names and email addresses.

What’s next?

The compromised reporting system has been taken offline and individuals who are affected are being contacted.

More than a million people, including students, school staff, and parents, have been affected following a data breach at Mathspace, according to the learning provider.

The company said, in a blog post, “unauthorised parties had accessed an internal reporting system used by Mathspace” and the exposed information included names and email addresses.

It said the attackers accessed the system between August 10 and August 27 during a period when a security patch had not been installed.

Mathspace said “attackers exploited a security vulnerability” in its self-hosted installation of software.

“We’re truly sorry this happened and are taking steps to prevent similar breaches in the future,” the company said.

“Protecting the information entrusted to us by students, families and schools is our responsibility.”

Mathspace confirmed a total of 1,079,819 people were affected in Australia and New Zealand.

The hackers exported information that included user IDs, usernames, first names, last names, email addresses, countries, time zones, user types, email-verification status, last-active date, last-login date and date joined.

But the company said not every person had all those fields of data stolen.

Mathspace make clear that no academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed.

“The exposed data did not include records linking user accounts to their schools,” the blog said.

Mathspace advised people to:

  • Check unexpected messages independently
  • Not disclose passwords or verification codes in response to a message
  • Use a unique password for each account.

It also urged people to watch for unusual account activity, and if anybody wanted to report suspicious messages or activity they should contact [email protected].

The compromised reporting system has been taken offline.

Mathspace said it had contacted schools, cyber security authorities and education departments and was now contacting affected individuals.

The company said it did not yet know who was responsible for the breach and had found “no evidence so far” that the stolen information had been published, shared or sold.

Steve Hunter, director of engineering, APAC, at cybersecurity and AI company Arctic Wolf, said the Mathspace incident highlighted how difficult it could be for organisations to keep on top of software vulnerabilities.

“Rather than playing ‘Whack-a-Mole’ every time a new vulnerability appears, organisations need to take a more risk-based approach,” he said.

“The priority should be knowing what systems and software you have, understanding where the biggest risks sit, and having a clear process for acting when a critical security warning comes through.”