Skip to content
Tech News
← Back to articles

Mathspace discloses data breach affecting over 1 million people

read original get Yubico YubiKey 5C NFC Security Key → more articles
Why This Matters

Mathspace, an edtech platform used by thousands of schools, says attackers exploited a vulnerability in its self-hosted Metabase reporting tool to steal data on more than 1 million students, parents, and staff in Australia and New Zealand. The breach is another reminder that children's data held by education vendors is a high-value target, and that internal analytics tools are often the weak link. Intruders had access for weeks before detection.

Key Takeaways
Worth a Look

Yubico YubiKey 5C NFC Security Key — Breaches like this one show how much damage a single stolen admin login can do — a hardware security key makes account takeover far harder than a password alone. The YubiKey 5C NFC works over USB-C or by tapping to your phone, and it protects logins on Google, Microsoft, password managers and more. It's a pocket-sized upgrade for anyone whose family data just showed up in someone else's download.

See Yubico YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system.

Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in Australia and 3,557 abroad according to statistics reported by the company in 2023).

In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attackers gained access to the company's systems and stole personal information belonging to school staff and students, as well as their parents and guardians.

"On 3 September 2026, we confirmed that unauthorised parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff. Mathspace staff records were also affected," Savoy said.

"Attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting. The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login."

While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27.

Savoy noted that only students and school staff from Australia and New Zealand had their data stolen in the incident. Although the attackers didn't steal credentials, academic records and information, in some cases they may have been able to link some impacted accounts to their schools.

"A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected," he added.

"No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools. However, for schools with identifiable email domains, we understand this may be possible."

Savoy also warned affected students and school staff that attackers may target them using the stolen data, and advised them to watch for suspicious account-related activity, such as changes to account details and password-reset messages.

... continue reading