Australian tutoring platform Mathspace has disclosed a breach impacting student data alongside that of parents and teachers, with more than 1 million Australians and New Zealanders impacted.
“On 3 September 2026, we confirmed that unauthorised parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff. Mathspace staff records were also affected,” the company said in a disclosure notice last updated on 6 September.
“The exposed information included names and email addresses, along with account details described below. Customer passwords, single sign-on (SSO) tokens and other customer authentication credentials were not exposed.
“We have concluded our investigation into the scope of the exposure and identified the affected accounts and records.”
According to Mathspace, an unidentified attacker exploited an unpatched vulnerability in Mathspace’s self-hosted installation of the internal reporting platform Metabase. This vulnerability had been disclosed on 6 August, but Mathspace said its internal vulnerability notification process did not catch the advisory, so the installation remained vulnerable.
“Our investigation identified unauthorised access dating back to 10 August 2026, Australian Eastern Standard Time. We confirmed that information was downloaded from our Australian reporting database on 27 August,” Mathspace said.
“During our subsequent review of historical access logs, we confirmed on 3 September that unauthorised access had occurred before the update was applied. At the time of updating, we did not complete the additional compromise checks recommended for potentially affected systems.”
The company said it is investigating why the advisory was not acted upon and is updating its processes. However, more than 1 million individuals have since been impacted by the oversight.
“A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected,” Mathspace said.
“The exported information included user ID, username, first name, last name, email address, country, time zone, user type, email-verification status, last-active date, last-login date and date joined. The affected records relate to students, parents or guardians, teachers and Mathspace staff. Not every field was present for every person.”
Mathspace has confirmed that no academic or learning data was compromised, nor were passwords or authentication tokens. The company is nonetheless urging users to change any passwords reused on other services.
As of 3 September, Mathspace remains offline as work continues to remediate the breach. On 4 September, the company also informed the Office of the Australian Information Commissioner (OAIC), the Australian Cyber Security Centre (ACSC), New Zealand’s Office of the Privacy Commissioner, and New Zealand’s National Cyber Security Centre.
“Our remaining work includes notifying affected individuals (we started this on the 6th of September), responding to school requests and completing recovery checks for the reporting system,” Mathspace said.
“Our post-incident review will address how we receive and escalate critical security advisories and how we check for compromise after a vulnerability is disclosed. We will report the resulting changes and their implementation status here.”
No threat actor has claimed responsibility for the hack as of the time of publication.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.