Skip to content
>_ITDITDWeb Security Platform

Security Guides

Once a fix is out, attackers move within days — the Mathspace internal reporting tool breach and what parents and schools should do

On September 5, 2026, maths learning platform Mathspace said attackers exploited a vulnerability in its self-hosted internal reporting system and downloaded names, email addresses and account details of 1,079,819 students, parents and staff in Australia and New Zealand. What families and schools should do.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 13 min read

For: students, parents and teachers in Australia and New Zealand who use (or used) the maths learning platform Mathspace, including families who have moved there from abroad, plus school IT staff and anyone who runs an education service. This article is based on Mathspace's official blog post and guidance from the Office of the Australian Information Commissioner (OAIC) and New Zealand's Office of the Privacy Commissioner, and does not cover attack techniques.

What parents and students should do

1

Don't sign in from links in messages claiming to be Mathspace or your school

Mathspace warns that names, email addresses and account details make impersonation attempts more convincing, and asks people to stay cautious even if a message uses your name or refers accurately to your school or this incident. To check, open the Mathspace website or app yourself, or use contact details you found separately on an official website (basics: What is phishing?).

2

Agree with your child: codes and passwords are never shared

Mathspace says do not disclose passwords or verification codes in response to a message, and tells students who are unsure what to do to ask a parent, guardian or teacher. Children tend to comply with anything framed as "from your teacher" or "about your homework". If English-language notices are hard to follow at home, making sure your child understands this one rule already covers most of the risk.

3

If you reused the password elsewhere, change it there

Mathspace is not requiring a password reset because of this incident, but if you reused your Mathspace password on another service, change that password to a unique one. The OAIC likewise advises, when contact details are exposed, using strong email passwords you haven't used elsewhere and turning on multi-factor authentication where possible (Choosing a password manager).

4

Watch for password-reset emails you didn't request

Mathspace asks people to pay attention to unexpected password-reset emails or changes to account details, and to change the password and contact the company if they notice suspicious activity.

5

To check, write a new email to the official address

Mathspace says to start a new email to data-breach-response@mathspace.co rather than replying to a message, or to navigate to its website yourself and use its support channels. It says former or inactive users can also be affected, and they can ask too.

6

Know where to get help

The OAIC points to Scamwatch, the Australian Government's scam information site, for help recognising scams. New Zealand's Office of the Privacy Commissioner says you can contact the NCSC for advice on a cyber issue, and points to the support service IDCARE if you are worried about identity misuse. For children's online safety, Mathspace itself points families to Australia's eSafety Commissioner. If you feel unsafe, contact the police (111 in New Zealand).

What school IT staff should do

1

Ask for your school's numbers and records

According to Mathspace, school administrators can contact data-breach-response@mathspace.co to request the number of affected students, staff and parents or guardians associated with their school, or details of the affected records; the company will arrange secure sharing where individual records are needed. Schools can also request an incident or forensic report.

2

Assume your email domain can reveal your school

The company says the exposed data did not include records linking user accounts to their schools, but that for schools with identifiable email domains, this may be possible. Expect fake messages that use your school's name, and tell parents plainly which channels official school communications arrive through.

3

Send guidance to parents through the school's official channels

Mathspace says it notified schools first so they could coordinate communications with their communities. Give parents the facts (what was and wasn't included) and the steps above through the school website or your usual parent app, and tell them to verify through those channels rather than links in notification emails.

What happened (from Mathspace's disclosure)

Everything below is as stated in Mathspace's official blog post (September 5, 2026, updated September 8). Dates are as the company gives them.

  1. August 6, 2026

    The developer of the reporting software Mathspace used publishes a critical security advisory and patched versions. Mathspace says its vulnerability-notification process did not identify and escalate the advisory.
  2. August 10

    Earliest unauthorised access identified by the company's investigation (Australian Eastern Standard Time).
  3. August 27

    Information is downloaded from the Australian reporting database (confirmed later).
  4. August 29

    Mathspace updates the software after a later notice from the developer comes to its attention. It says it did not complete the recommended additional compromise checks at this point.
  5. September 3

    A review of historical access logs confirms unauthorised access before the update. The reporting system is taken offline, its API keys revoked, database access accounts disabled and database passwords changed.
  6. September 4

    Notifications to school contacts begin. Reports to the OAIC, ASD's ACSC, New Zealand's Office of the Privacy Commissioner and NCSC; Australian state and territory education departments notified.
  7. September 5

    Public disclosure on the company blog.
  8. September 6

    Notifications to individuals begin (earlier than first communicated to schools, at schools' request).
1,079,819
People affected (students, staff, parents and guardians combined)
2 countries
Australia and New Zealand only
4 days
From the fix being published (Aug 6) to the first unauthorised access (Aug 10)
Not included
Passwords, SSO, grades, learning records (per the company)
What Mathspace has disclosed
Data taken
User ID, username, first and last name, email address, country, time zone, user type, email-verification status, last-active date, last-login date, date joined. Not every field was present for every person
People involved
Students, parents or guardians, teachers and Mathspace staff. Former or inactive users can be affected if their information was retained in the reporting database
Not included
Passwords (hashes), authentication tokens, SSO credentials, API credentials, academic records, learning activities, results, assessment records, and records linking accounts to schools
Cause (per the company)
A vulnerability in its self-hosted internal reporting software that allowed administrator access without a legitimate login
Misuse
No evidence so far of publication, distribution, sale or misuse. Attacker identity unknown
Containment
Reporting system taken offline; all of its API keys revoked; its data-platform access accounts disabled; database passwords changed
Notifications
OAIC, ASD's ACSC, New Zealand's Office of the Privacy Commissioner and NCSC, Australian state and territory education departments

Reading note: we don't name the software product

Mathspace has named the reporting software it used. We do not name the developer, which is not the subject of this incident, and refer to it only as "the developer of the reporting software"; the defensive lesson is the same for any product. No breakdown of the total by country or user type has been published.

This site's view: "internal" tools are the ones that don't get patched

What stands out here is that the leak came not from the app customers use but from an internal tool for looking at numbers. Put the company's own dates in a row and the intrusion and the download both fall between the fix being published and the fix being applied.

Aug 6

Developer publishes fix; internal alerting misses it

Aug 10

First unauthorised access

Aug 27

Data downloaded

Aug 29

Updated; no compromise check

Running unpatched: Aug 6 – Aug 29

Patched but unchecked: Aug 29 – Sep 3 (found by log review)

Lessons: (1) assign someone to follow advisories for internal tools (2) after patching, check for compromise back to the advisory date

The sequence from fix to confirmation, based on Mathspace's account. Top band: the period the tool ran unpatched. Bottom band: the period after patching when no compromise check was done.

Internal tools that get left for later

  • Reporting and analytics dashboards, admin panels, internal wikis
  • Set up because someone found it handy; no clear owner
  • Nobody subscribes to the developer's security advisories
  • Holds a database account that can read everything

The same tools, treated as production

  • On the inventory, with an owner and a known exposure (internal only or reachable from outside)
  • The developer's advisories reach the owner directly
  • Critical advisories are patched on the production deadline, then checked for compromise
  • The database account is read-only and limited to the columns needed

Reporting tools are for staff looking at numbers, so they are easy to think of as "not production". In practice they often hold database accounts and API keys that reach straight into the data platform. In this incident, to contain it, Mathspace revoked all of the reporting tool's API keys and disabled its data-platform access accounts. In other words, anything holding keys to production data is production, however internal its screens look. Four things operators can do today:

1

Inventory the software you run yourselves

List everything you host yourselves, including reporting, analytics, monitoring and internal wikis, with an owner and where it can be reached from (internal only, or also from outside). See Security inventory for how to build the list.

2

Route each developer's advisories to a named owner

Mathspace names its vulnerability-notification process failing to pick up the advisory as part of what went wrong. For each item on the inventory, make sure the developer's security advisories or release notices reach the owner. For deciding what to patch first, see CVSS, EPSS and KEV.

3

After patching, check for compromise back to the advisory date

Mathspace says it did not complete the recommended additional compromise checks when it updated. For a critical vulnerability, applying the patch is not the finish line. Run any checks the developer recommends, and review access logs from the advisory date onward for unfamiliar administrator accounts or sessions and bulk exports (full process: Fixing dependency CVEs for real).

4

Narrow the data and privileges the reporting tool gets

Make the reporting tool's database account read-only and limited to views exposing only the tables and columns it needs. Mathspace says information on people no longer using the service was retained in the reporting database, which is why they were affected. A rule for deleting or anonymising personal data the reports no longer need shrinks what can leak.

This site's view: if you hold children's data, decide what to keep by asking what hurts if it leaks

These fields look light next to grades or home addresses. But a child's name and email address, the user type "student", and the last date they logged in are enough to send "your homework is overdue" or "your account will be suspended" to children who really use the service. The company's acknowledgement that a school may be inferable from its email domain comes from the same logic. Education-service operators should ask whether reports truly need names and email addresses at all. Most reporting works with internal IDs alone.

We also covered an education incident in which course enrollment data and messages were taken from the Canvas learning management system (the Canvas (Instructure) breach).

In the same period, booking data from UK airports was also obtained (the Manchester Airports Group (MAG) data breach).

Sources (public record)

The facts in this article come from the public sources below. We do not repeat speculation from press coverage, unpublished breakdowns, or information about the attackers.

  • Mathspace, "Mathspace data breach: what happened and what affected users should know" (September 5, 2026, updated September 8) — blog.mathspace.co
  • OAIC, "Respond to a data breach notification" — oaic.gov.au
  • New Zealand Office of the Privacy Commissioner, "My information was part of a privacy breach. What can I do?" — privacy.org.nz
  • eSafety Commissioner (the children's online safety resource Mathspace points to) — esafety.gov.au

Update history

2026-09-30: First version, based on Mathspace's official blog post (September 8 update) and guidance for individuals from the OAIC and New Zealand's Office of the Privacy Commissioner. The company says it will report the changes from its post-incident review and their implementation status on its blog; we will update this page when it does.

FAQ

QWhat was exposed in the Mathspace data breach?
A

According to Mathspace, the exported information included user ID, username, first name, last name, email address, country, time zone, user type, email-verification status, last-active date, last-login date and date joined. Not every field was present for every person. The records relate to students, parents or guardians, teachers and Mathspace staff.

QWere passwords or grades exposed?
A

Mathspace says customer passwords (including hashes), single sign-on (SSO) tokens, other authentication credentials and API credentials were not exposed, and neither were academic records, learning activities, results or assessment records. It is not requiring a password reset because of this incident, but if you reused your Mathspace password on another service, it recommends changing that password to a unique one.

QHow many people were affected?
A

According to Mathspace, 1,079,819 people were affected, counting students, staff and parents or guardians together, and only people in Australia and New Zealand were affected. No breakdown by country or user type has been published. School administrators can ask the company for the numbers and records associated with their school.

QHow do I find out whether my child or I was affected?
A

Mathspace began notifying school contacts on September 4 and individuals from September 6. To verify a message or ask about your information, the company says to start a new email to data-breach-response@mathspace.co rather than replying, or to navigate to its website yourself and use its support channels. It says former or inactive users can also be affected if their information was retained in the reporting database.

QWas the data published?
A

Mathspace says it has no evidence so far that the data has been published, distributed, sold or otherwise misused, and that the identity of the attacker remains unknown.

QWhat caused it?
A

According to Mathspace, attackers exploited a vulnerability in its self-hosted installation of software used for internal reporting, which allowed them to obtain administrator access without a legitimate login. The software's developer published a critical security advisory and patched versions on August 6, 2026, but Mathspace's vulnerability-notification process did not identify and escalate it; the company updated on August 29. It also says it did not complete the recommended additional compromise checks at the time of updating, and that it is changing both processes.

QHave regulators been notified?
A

Mathspace says that on September 4 it reported the incident to the Office of the Australian Information Commissioner (OAIC), the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), New Zealand's Office of the Privacy Commissioner and New Zealand's National Cyber Security Centre (NCSC), and also notified Australian state and territory education departments.