Mathspace Breach Exposes Data of 1.08 Million in Australia, New Zealand

Mathspace says a breach exposed data tied to nearly 1.08 million people in Australia and New Zealand after attackers exploited a self-hosted Metabase flaw.

Written By
LT
Liz Ticong
Sep 7, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Nearly 1.08 million people across Australia and New Zealand have been affected by a Mathspace data breach.

The education platform said on Sept. 3 that an attacker accessed its internal reporting system and downloaded records linked to students, parents or guardians, teachers, and employees.

A critical security warning for the exploited software had already been issued before the intrusion. How the alert was handled became a key part of the breach.

A missed security alert opened the breach window

Attackers entered through a self-hosted Metabase installation used for internal reporting. Metabase had warned customers on Aug. 6 about a critical flaw that could allow unauthorized access to connected data, according to its security advisory.

Mathspace later acknowledged that its vulnerability-notification process failed to escalate the warning. Unauthorized access began four days after the advisory, and data was downloaded before the service was patched later in the month.

Installing the update did not immediately reveal the earlier compromise. Recommended checks were not completed at the time, and a later review of historical logs confirmed the intrusion. 

Former users and school communities remain in scope

According to Mathspace, the downloaded dataset included names, email addresses, account IDs and user types. Some records also contained country or time-zone information and dates associated with account activity.

Passwords and authentication material such as SSO tokens or API credentials were not downloaded. Academic records, learning activity, and assessment results were also excluded.

Former and inactive users are still affected because older account records remained in the reporting database. School associations were not directly exported. 

Schools and affected individuals have been notified, as well as privacy and cybersecurity authorities in both countries. Mathspace took the reporting system offline and began additional incident response and recovery work. So far, the company says it has found no evidence the stolen data was published, sold, or otherwise misused.

Advertisement

Affected users should verify breach messages independently

Australian and New Zealand students, parents, teachers, and staff should be alert for impersonation or phishing attempts using exposed account details or recognizable school email domains.

Affected users and school administrators can reduce that risk by treating breach-related communications with extra scrutiny.

  • Go directly to official sites. Open Mathspace or a school website yourself rather than following links in unsolicited breach notices or account alerts. Do not provide passwords or verification codes simply because a sender knows accurate personal details. 
  • Former users should verify their status through official channels. Use Mathspace’s breach page or official contact options. If you reused a password elsewhere, changing it is still good security practice even though Mathspace says passwords were not stolen. 
  • Schools and IT teams should give families a known verification channel. Institutions should make clear how legitimate breach communications will arrive and reinforce email security controls against impersonation. Teams running self-hosted Metabase should also confirm patched versions and inspect historical activity for evidence of compromise before the fix was applied.

Schools and affected users across Australia and New Zealand should remain alert for phishing or impersonation attempts that use accurate details from the stolen records.

More cybersecurity news: CISA’s latest KEV update includes seven vulnerabilities already under active attack, with several affecting widely used AI and web infrastructure. 

LT

Liz Ticong is a technology writer specializing in artificial intelligence, cybersecurity, software reviews, and emerging business technologies. With more than a decade of professional writing experience and over five years contributing technology content for TechnologyAdvice, she helps readers understand complex technologies and evaluate the tools that best fit their needs. Liz has extensive experience researching, testing, and analyzing software platforms, AI tools, and technology solutions. Her work includes in-depth software reviews, buyer’s guides, product comparisons, and technology news coverage designed to help businesses make informed purchasing and implementation decisions. She regularly evaluates AI applications, automation tools, cybersecurity solutions, and business software, providing practical insights based on hands-on testing and research. In addition to her work with TechnologyAdvice, Liz has contributed technology content to leading industry publications, including eWeek and TechRepublic. Her background in technical writing and software analysis enables her to translate complex technical concepts into clear, actionable guidance for both business and technology audiences. Liz holds a bachelor's degree in Broadcast Communication from the Polytechnic University of the Philippines and continues to expand her expertise through ongoing education in artificial intelligence and emerging technologies. Through her writing, she helps readers navigate a rapidly evolving technology landscape with practical, research-driven insights and real-world product analysis.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.