SecuritySeptember 8, 20267 min read

What to Do After the Mathspace Data Breach (1.08M Users)

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the Mathspace Data Breach (1.08M Users)

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

Mathspace has disclosed a breach affecting 1,079,819 students, parents, guardians, and school staff across Australia and New Zealand. Attackers exploited a critical flaw in its self-hosted Metabase reporting system and took names, email addresses, and account metadata. Passwords, SSO tokens, and academic records were not exposed. Here is what to do.

What Happened

Mathspace is an online mathematics learning platform used widely in Australian and New Zealand schools. The breach did not hit the teaching platform itself but an internal reporting system — a self-hosted instance of Metabase, a business-intelligence tool that sat connected to the company's Australian reporting database.

The flaw exploited is tracked as CVE-2026-72898, an unauthenticated SQL injection reachable through Metabase's password-reset API endpoint. It carries a maximum CVSS score of 10.0 because it lets an attacker inject arbitrary SQL and seize administrator access without any valid credentials. A patch was published on August 6, 2026.

Mathspace did not apply it. Unauthorised access to its reporting database began on August 10, 2026 — four days after the fix became available. Attackers exfiltrated data on August 27. Mathspace only updated its Metabase instance on August 29, after a separate later notice drew its attention to the advisory. The company has since acknowledged that its "existing vulnerability-notification process did not identify and escalate that advisory for action," and has taken the compromised reporting system offline.

What Was Exposed — and What Was Not

The stolen data covers 1,079,819 students, their parents or guardians, and school staff in Australia and New Zealand. The fields taken were account metadata rather than learning content:

  • Usernames
  • First and last names
  • Email addresses
  • Country and time zone
  • User type (student, teacher, parent or guardian, staff)
  • Email-verification status
  • Last-active date, last-login date, and date joined

Mathspace states that the following were not exposed: passwords and password hashes, single sign-on tokens, authentication tokens, API credentials, academic records, learning activity, results, and assessment records. The exported data also did not include records linking user accounts to their schools.

The Good News, Honestly Stated

No credentials and no financial data were taken, so this is not a breach that leads directly to account takeover or fraud. The realistic risk here is targeted phishing: an attacker who knows a child's name, their parent's name and email, and that both use a specific school maths platform can write a very convincing message. Treat this as a phishing-preparedness event, not a credit-freeze event.

Step 1: Verify Any "Mathspace" Message Before Acting

The exposed data set is close to ideal phishing fuel — real names, real email addresses, and a confirmed relationship to a specific service. Expect messages that claim to be a breach notification, a password reset, or a request to "re-verify" an account.

  • Never click a login or reset link in an email about this breach. Type the Mathspace address yourself or use your school's portal.
  • Check the sender's full domain, not the display name.
  • Treat urgency as a warning sign. Legitimate breach notices do not demand action within the hour.
  • Never provide payment details — Mathspace has no reason to ask, and no legitimate breach response requires a fee.

Step 2: Change the Password Anyway if You Reused It

Passwords were not exposed, so a password change is not strictly required. But if the password on your or your child's Mathspace account is used anywhere else, change it everywhere it appears. Credential reuse is the mechanism that turns one small breach into several serious ones, and attackers who know an email address is active will try it against other services regardless of where it came from.

Turn on two-factor authentication anywhere it is offered, particularly on the email address that appeared in the breach.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 3: Talk to Children About Messages That Use Their Name

This breach exposed data about minors, including their names and the fact that they use a school learning platform. Children are less likely to spot a message that uses their real name and references their schoolwork.

  • Explain that a company they use had names and emails stolen, and that messages may arrive that look official.
  • Set a simple rule: no clicking links in unexpected emails about school accounts, and check with a parent first.
  • Review which email address the child's school accounts use, and whether it is also used for anything sensitive.

Watch for Fake Class-Action and Compensation Offers

Breaches involving children reliably attract scams offering compensation, legal claims, or "identity protection for minors" in exchange for a Social Security or Tax File Number and a payment. Mathspace's breach did not expose government identifiers. Anyone asking you for one in connection with it is running a scam.

Step 4: Reduce the Data That Makes Phishing Work

A phishing email is convincing in proportion to how much the sender already knows about you. Names and email addresses from this breach become far more dangerous when combined with a home address, phone number, employer, and a list of family members — and that information is published openly on data broker and people-search sites, not hidden on criminal forums.

PrivacyOn removes your personal information from 100+ data broker and people-search sites, refiles automatically when brokers republish you, and includes dark-web monitoring that alerts you if your email appears in a new dump. Family plans cover up to five household members from $8.33/month, and the free scan shows what is currently published about your household without asking you to sign up.

What Schools and Parents Should Ask For

If your school uses Mathspace, it is reasonable to ask the school for three things: confirmation of whether its students were in the exported data, what Mathspace has told the school about remediation, and what the school's own process is for tracking vendor security advisories. The root cause here was not a sophisticated attack — it was a published critical patch that sat unapplied for 23 days. That is a process failure any organisation can and should be asked about.

The Bottom Line

The Mathspace breach exposed contact details and account metadata for more than a million students, parents, and school staff, but not credentials or academic records. Nobody needs to freeze credit over it. What everybody in an affected household should do is treat unexpected messages about school accounts with suspicion, stop reusing passwords, and shrink the public data footprint that makes targeted phishing believable in the first place.

Frequently Asked Questions

How many people were affected by the Mathspace data breach?

1,079,819 students, parents or guardians, and school staff, all located in Australia and New Zealand. Attackers accessed an internal Metabase reporting system from August 10, 2026 and exfiltrated data on August 27, 2026. Mathspace patched the vulnerability on August 29 and has taken the affected system offline.

Were passwords exposed in the Mathspace breach?

No. Mathspace states that passwords, password hashes, single sign-on tokens, authentication tokens, and API credentials were not exposed. Academic records, learning activity, results, and assessment records were also not taken. The stolen data was account metadata: usernames, names, email addresses, country, time zone, user type, and login dates.

Do I need to freeze my credit after the Mathspace breach?

No. No Social Security numbers, Tax File Numbers, government identifiers, or financial data were exposed, so this breach does not create a direct credit-fraud risk. The realistic risk is targeted phishing using real names and email addresses. Anyone contacting you for a government ID number over this breach is running a scam.

How did the Mathspace breach happen?

Attackers exploited CVE-2026-72898, an unauthenticated SQL injection in Metabase's password-reset API endpoint with a CVSS score of 10.0. A patch was released on August 6, 2026, but Mathspace's self-hosted instance was not updated until August 29 — the company has acknowledged that its vulnerability-notification process failed to escalate the advisory.

My child's data was exposed. What should I do?

Talk to them about messages that use their real name or mention their schoolwork, and set a rule that they check with you before clicking links in emails about school accounts. Change any password reused elsewhere, enable two-factor authentication on the family email address, and reduce the household data published on people-search sites, which is what makes targeted phishing convincing.

How do I stop targeted phishing after a breach like this?

Cut off the supporting information. Phishing works when the sender can reference your address, phone number, employer, or relatives — details published by data brokers rather than leaked by the breach. A service like PrivacyOn removes your household from 100+ broker and people-search sites, keeps refiling when they relist you, and monitors the dark web for your email address from $8.33/month.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families