Platform safety · Blog

The Mathspace breach: what it means for your family

By Ray & Renie Robinson, Aunty Bea  ·  8 September 2026

If your child does maths homework on a laptop, there's a fair chance the program is Mathspace. On 3 September 2026 the company confirmed that unauthorised parties had got into one of its internal systems and downloaded records. It says 1,079,819 people are affected — students, parents and guardians, and school staff — and that only people in Australia and New Zealand are involved.

That's a lot of families. It's also a plain reminder that the apps holding our kids' details aren't only the social ones. A maths program isn't social media and it isn't a game. It still knows your child's name, their email address and when they last logged in.

Here's what was taken, what wasn't, and what's worth doing tonight. No panic required. A few checks, one conversation.

What actually happened

Mathspace says attackers exploited a security vulnerability in its self-hosted installation of Metabase, a piece of software the company uses for internal reporting. Its investigation found unauthorised access dating back to 10 August, and information was downloaded from its Australian reporting database on 27 August. The breach was confirmed on 3 September, and the company published its notice on 5 September.

There is a timing detail worth knowing. According to iTnews, Metabase had issued a security advisory on 7 August telling customers to upgrade their self-hosted installations immediately. Mathspace's founder and chief technology officer, Alvin Savoy, told iTnews the company updated its instance on 29 August, after a later Metabase notice came to its attention. iTnews reports the vulnerability carries the maximum severity rating of 10.0.

Who did it is not known. Mathspace told the ABC it did not yet know who was responsible, and that it had found "no evidence so far" that the stolen information had been published, shared or sold. The company says it has reported the incident to the Office of the Australian Information Commissioner and the Australian Cyber Security Centre, and to their New Zealand counterparts, and that affected people are being contacted.

What was taken — and what wasn't

Taken, in Mathspace's own list: user ID, username, first name, last name, email address, country, time zone, user type, email-verification status, last-active date, last-login date and date joined. The ABC notes that not every person had every one of those fields taken.

Not taken: passwords (including the scrambled versions companies store), single sign-on tokens and other login credentials, and — for the kids — no academic records, learning activities, results or assessment records.

The "not taken" list is the good news: nobody can log in as your child with what was stolen. The "taken" list is why this still matters. A name, a school email address and the date someone last logged in is a scammer's starter kit. "Hi Jack, we noticed you last logged in to Mathspace on Tuesday — click here to secure your account" is a message a twelve-year-old would believe.

Why it matters for Australian families

The Australian Cyber Security Centre's advice after any breach is blunt about this: scammers may pose as the organisation involved, by email, text or phone, and any message should be confirmed with an official source such as the company's own website. Its example is exactly the one to expect here — an email asking you to reset a password because it was compromised.

Two things make a school-platform breach different from, say, a retailer's. First, many children's Mathspace logins are their school email addresses, so the scam messages may land in an inbox you never see. Second, parents and guardians are on the affected list too. This is your data as much as your child's.

What you can do tonight

  1. Ask your child whether they use Mathspace. Many schools set homework through it. If they do, expect a notice from Mathspace or the school — and know that the genuine one won't ask for a password or a code.
  2. Treat any "Mathspace" or "your school" message that carries a link, a code or a sense of urgency as suspicious. The ACSC's advice is not to use the links or contact details in the message: go to the official website yourself, or ring the school office.
  3. Passwords. Mathspace says passwords weren't exposed. Even so, if your child (or you) uses the Mathspace password anywhere else, change those other accounts — the ACSC's rule is a unique password for every online account.
  4. Turn on multi-factor authentication wherever an account offers it. The ACSC lists it as the first thing to do after a breach.
  5. Keep an eye out for a few weeks. The ACSC says to keep checking for unauthorised activity even once your accounts are secure.
  6. Have the conversation. The one rule that defuses most of this: if a message asks for a code or a password, show a grown-up before you do anything. Say it tonight, and again next week.

If something does go wrong — money lost, an account taken over — report it through the ACSC's ReportCyber service, and tell the school.

A data breach is one more reason the online-safety conversation belongs at the kitchen table, not just in the settings menu. If you want a way in, our guide on how to talk to your kid about online safety is a good place to start: auntybea.app/guides/how-to-talk-to-your-kid-about-online-safety

Questions parents ask

Mathspace says no. Passwords, password hashes, single sign-on tokens and other login credentials were not exposed.
No. Mathspace says no academic records, learning activities, results or assessment records were exposed.
Mathspace puts it at 1,079,819 people — students, parents or guardians, and school staff — and says only people in Australia and New Zealand were affected.
The company told the ABC it is contacting affected individuals. If you're not sure a message is genuine, check the notice on Mathspace's own website rather than clicking anything in an email.
Mathspace told the ABC it had found "no evidence so far" that it had been published, shared or sold. That can change, which is why the ACSC advises watching your accounts for a while.

Sources

  1. Mathspace — "Mathspace data breach: what happened and what affected users should know" — Alvin Savoy, 05 Sep 2026, updated 6 Sep 2026
  2. ABC News — "More than 1 million users affected in Mathspace data breach across Australia and New Zealand" — posted Mon 7 Sep 2026, 4:53pm
  3. iTnews — "Late patching of Metabase SQLi bug claims Sydney's Mathspace" — Juha Saarinen, 8 Sep 2026 11:33AM
  4. Australian Cyber Security Centre — "Report and recover from a data breach"

Read next: our guide →

Aunty Bea helps Australian families with what comes next, quietly. You'll never scroll your child's messages in Aunty Bea. You get a plain-English summary of what looked risky, and how to talk about it.

Get started free →