Nearly 1.08 million people across Australia and New Zealand have been affected by a Mathspace data breach.
The education platform said on Sept. 3 that an attacker accessed its internal reporting system and downloaded records linked to students, parents or guardians, teachers, and employees.
A critical security warning for the exploited software had already been issued before the intrusion. How the alert was handled became a key part of the breach.
A missed security alert opened the breach window
Attackers entered through a self-hosted Metabase installation used for internal reporting. Metabase had warned customers on Aug. 6 about a critical flaw that could allow unauthorized access to connected data, according to its security advisory.
Mathspace later acknowledged that its vulnerability-notification process failed to escalate the warning. Unauthorized access began four days after the advisory, and data was downloaded before the service was patched later in the month.
Installing the update did not immediately reveal the earlier compromise. Recommended checks were not completed at the time, and a later review of historical logs confirmed the intrusion.
Former users and school communities remain in scope
According to Mathspace, the downloaded dataset included names, email addresses, account IDs and user types. Some records also contained country or time-zone information and dates associated with account activity.
Passwords and authentication material such as SSO tokens or API credentials were not downloaded. Academic records, learning activity, and assessment results were also excluded.
Former and inactive users are still affected because older account records remained in the reporting database. School associations were not directly exported.
Schools and affected individuals have been notified, as well as privacy and cybersecurity authorities in both countries. Mathspace took the reporting system offline and began additional incident response and recovery work. So far, the company says it has found no evidence the stolen data was published, sold, or otherwise misused.
Affected users should verify breach messages independently
Australian and New Zealand students, parents, teachers, and staff should be alert for impersonation or phishing attempts using exposed account details or recognizable school email domains.
Affected users and school administrators can reduce that risk by treating breach-related communications with extra scrutiny.
- Go directly to official sites. Open Mathspace or a school website yourself rather than following links in unsolicited breach notices or account alerts. Do not provide passwords or verification codes simply because a sender knows accurate personal details.
- Former users should verify their status through official channels. Use Mathspace’s breach page or official contact options. If you reused a password elsewhere, changing it is still good security practice even though Mathspace says passwords were not stolen.
- Schools and IT teams should give families a known verification channel. Institutions should make clear how legitimate breach communications will arrive and reinforce email security controls against impersonation. Teams running self-hosted Metabase should also confirm patched versions and inspect historical activity for evidence of compromise before the fix was applied.
Schools and affected users across Australia and New Zealand should remain alert for phishing or impersonation attempts that use accurate details from the stolen records.
More cybersecurity news: CISA’s latest KEV update includes seven vulnerabilities already under active attack, with several affecting widely used AI and web infrastructure.





