A security breach at the online mathematics platform Mathspace has exposed the personal information of more than one million students, parents, and teachers across Australia and New Zealand. The incident highlights growing security vulnerabilities in the educational software programs schools use daily. As school communities handle the fallout, the breach shows the need for stronger data protections in education.
What Happened
On September 3, 2026, Mathspace confirmed a security breach and notified regulatory bodies like New Zealand’s Office of the Privacy Commissioner and the Australian Office of the Privacy Commissioner.
The breach stemmed from a vulnerability (CVE-2026-72898) in Metabase, an internal reporting tool used by Mathspace. Although a patch was released on August 6, 2026, Mathspace did not apply it until August 29, 2026, 23 days later. During this window, unauthorized users gained access to the system and downloaded data between August 10 and August 27.
According to the official Mathspace disclosure, the compromised files included names, email addresses, user IDs, usernames, time zones, and login metadata for exactly 1,079,819 individuals. No passwords, financial records, or academic grades were stolen. However, ABC News reported that email addresses could still allow malicious actors to link users to specific schools if those schools use easily identifiable email domains.
The Bigger Picture
This event is part of a pattern of security failures in the education technology sector. For example, a previous breach involving the Canvas learning management system compromised the personal data of millions of users globally. Similarly, a massive security failure at PowerSchool exposed the records of roughly 62 million students after a hacker accessed a customer support portal that lacked multi-factor authentication. That incident led to widespread federal litigation, as detailed in court records from the MDL litigation.
Schools are primary targets because they handle massive volumes of personal data. In Australia, cyber incidents have even forced schools like Reynella East College to take their entire computer networks offline. Internal administrative failures also pose risks. A recent audit in New South Wales revealed that weak privacy controls allowed two students to access 2,000 highly sensitive files regarding other pupils' mental health and behavioral diagnoses.
We previously reported on how school surveillance and security gaps expose student data, which showed the need for systemic reform in how school districts vet software vendors.
What This Means for Families
Even though no passwords or grades were leaked, the exposed names and email addresses put families at higher risk for targeted phishing scams. Hackers can use this information to draft convincing emails pretending to be school administrators or educational software providers.
The Mathspace security notice warns families to remain skeptical of unexpected communications, even those about the breach itself, as scammers often exploit the confusion following a public disclosure. School districts affected by such breaches have had to retroactively clean databases of sensitive information. This shows that security failures leave administrative and privacy concerns that affect graduated students and former staff for years.
What You Can Do
To stay safe, treat any email asking for passwords or login verification codes with suspicion. Always verify the sender's identity through a separate channel before clicking links.
Educators should ask school administrations to verify that all third-party platforms use multi-factor authentication. They should also demand strict patch-management schedules, such as the Australian Signals Directorate's 48-hour patching recommendation.
Finally, parents and schools should push for vendors to automatically delete student data when it is no longer needed for classroom instruction. This reduces the risk of future exposure.