THE Mathspace data breach has affected 1,079,819 people in Australia and New Zealand, with unauthorized parties gaining access to an internal reporting system and downloading user information. Mathspace confirmed the incident on 3 September 2026, stating that the exposed records involve students, parents or guardians, teachers, and Mathspace staff.
The affected data include names, email addresses, and account details, while customer passwords, single sign-on (SSO) tokens, and other authentication credentials were not exposed. There is currently no evidence that the information has been published, sold, distributed, or otherwise misused, and the attacker’s identity remains unknown.
The breach arose from a vulnerability in Mathspace’s self-hosted Metabase installation used for internal reporting, which allowed attackers to obtain administrator access without a legitimate login. The article reports no known misuse of the data to date, but the incident highlights the risk posed by flaws in internal tooling that can elevate access.
Mathspace’s disclosure and the preliminary evidence suggest a breach of internal systems rather than a direct customer credential compromise, and the company has indicated the affected party set includes students, parents or guardians, teachers, and staff. No CVEs or technical fallout are provided beyond the Metabase flaw, and the article does not detail a remediation timeline.