Mathspace confirms a data breach impacting over 1.07 million students, parents, and teachers after hackers accessed an internal system.
Popular online mathematics learning platform Mathspace has confirmed a major cybersecurity breach that exposed the personal data of over one million individuals.
Used by thousands of classrooms to deliver daily lessons, set homework tasks, and monitor student progress, the educational technology provider suffered an unauthorized intrusion into its internal computer systems.
Hackers managed to break into the company’s reporting server and download personal account records. The stolen information includes full names, email addresses, usernames, and account creation dates belonging to young students, their parents or guardians, school teachers, and internal company staff.
The formal data security disclosure was officially published by Mathspace leadership on Saturday, September 5, 2026, with public notifications continuing through Monday, September 7, 2026.
Following an extensive internal forensic investigation, the company confirmed that the breach specifically impacted 1,079,819 individuals located across Australia and New Zealand.
Computer logs revealed that unauthorized parties first gained access to the system on August 10, 2026, before downloading database records on August 27, 2026, weeks before security teams discovered the intrusion and shut down the affected servers.
The primary reason the cyberattack occurred is that an internal reporting tool used by Mathspace contained an unpatched software flaw.
The company was running a self hosted installation of third-party analytics software called Metabase. While the software developer issued an urgent security patch in early August 2026 to fix a critical hole, Mathspace’s internal updates were delayed.
Digital thieves exploited this security gap to obtain administrative control without needing a valid password, allowing them to download user information directly from the company’s Australian database.
Apologizing directly to affected families and educational institutions while detailing the exact scope of the incident, Chief Technology Officer at Mathspace Alvin Savoy stated that “on 3 September 2026, we confirmed that unauthorized parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff”.
Explaining how cybercriminals bypassed standard security checks to reach internal company databases, Alvin Savoy noted that “attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting. The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login”.
Reassuring users that sensitive academic results, financial details, and account passwords remained completely safe inside separate systems, Alvin Savoy added that “a total of 1,079,819 people were affected… No academic records, learning activities, results, assessment records, passwords, authentication tokens, SSO credentials, or API credentials were exposed”.
By taking the compromised reporting software offline, resetting access keys, and notifying government privacy regulators, Mathspace is taking necessary steps to secure its digital infrastructure.
Promptly fixing software flaws ensures that classroom learning tools stay safe, reliable, and secure for students, teachers, and families.

