Mathspace discloses data breach affecting over 1 million people
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after.
By Dillip Chowdary β’ Sep 07, 2026 β’ Source: BleepingComputer
What broke in Mathspace discloses data breach affecting
3. Review against Constraints: Word Count: Intro 1: 93 words *
Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in Australia and 3,557 abroad according to statistics reported by the company in 2023). In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attackers gained access to the company's systems and stole personal information belonging to school staff and students, as well as their parents and guardians.
Who is exposed by Mathspace discloses data breach affecting

"On 3 September 2026, we confirmed that unauthorised parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff. "Attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
What to do now about Mathspace discloses data breach affecting
Savoy noted that only students and school staff from Australia and New Zealand had their data stolen in the incident. See the full write-up from BleepingComputer via the source link for quotes and complete context.
Although the attackers didn't steal credentials, academic records and information, in some cases they may have been able to link some impacted accounts to their schools. "A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined.
How the Mathspace discloses data breach affecting issue works
"No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools.
What is still unknown about Mathspace discloses data breach affecting
Trezor revealed on August 13 that attackers stole the data of nearly 14,000 customers after hacking its shipping and logistics provider, ShipMonk. See the full write-up from BleepingComputer via the source link for quotes and complete context.
Developer Action Items
- β Inventory whether Mathspace discloses data breach runs in prod, CI, staging, or on laptops before you debate severity.
- β Confirm the vendor's fixed build for Mathspace discloses data breach from BleepingComputer, then schedule the patch window.
- β If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
- β Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
- β Treat unexpected emails that mention Mathspace discloses data breach (shipping, invoices, password resets) as phishing until verified.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
Advertisement