Mathspace breach exposes 23-day patch gap in school systems

Mathspace breach exposes 23-day patch gap in school systems

A data breach at Australian-founded learning platform Mathspace has exposed personal information belonging to more than 1 million students, parents and school staff across Australia and New Zealand, with the company confirming attackers exploited a critical software vulnerability that sat unpatched for more than three weeks.

Mathspace, which is used in thousands of schools across Australia, New Zealand, the United States and the United Kingdom, said an attacker gained access to its systems and stole personal information belonging to school staff, students, and their parents or guardians.

Mathspace confirmed a total of 1,079,819 people were affected, comprising students, staff, and parents or guardians, with only individuals in Australia and New Zealand affected.

A patch delayed by more than three weeks

The company traced the intrusion to a flaw in Metabase, an analytics tool it runs on its own servers for internal reporting. Mathspace said its investigation identified unauthorised access dating back to August 10 2026, and confirmed that information was downloaded from its Australian reporting database on August 27.

The company did not complete the compromise checks Metabase had recommended and did not identify the intrusion when it applied the software update.

Mathspace's chief technology officer, Alvin Savoy, said in a company blog post that the business confirmed on September 3 that unauthorised parties had accessed its internal reporting system and downloaded information on students, their parents or guardians, and school staff. The company said it is investigating why the initial advisory was not escalated and why compromise checks were not completed sooner, and is changing both processes as part of its incident response.

Exposed information included names and email addresses, along with account details, though customer passwords, single sign-on tokens and other authentication credentials were not exposed. Mathspace has taken the affected reporting instance offline, revoked API keys and reset access credentials as part of its response, according to the company's disclosure.

Part of a wider pattern in Australian schools

The incident follows a separate breach disclosed in January 2026, when the Victorian Department of Education confirmed unauthorised third parties had accessed a database containing student information spanning all 1,700 Victorian government schools, a system serving roughly 650,000 students.

That breach exposed student names, school-issued email addresses, year levels, school names and encrypted passwords, prompting the department to reset passwords across the entire government school system and prioritize new credentials for students sitting the Victorian Certificate of Education, according to the Australian Data Breach Archive.

Education recorded 81 notifications to the Office of the Australian Information Commissioner in 2025, tying for fifth among all sectors by volume, according to figures reported by Insurance Business Australia

Coalition's chief underwriting officer, Tiago Henriques, has said that as of July 2025, the insurer calculated 61,764 known software vulnerabilities would technically qualify for exclusions some cyber insurers apply to unpatched, high-severity flaws, yet only 1.1% of those had been confirmed as actively exploited.

Regulatory scrutiny across two countries

The Mathspace breach triggered notification obligations in both Australia and New Zealand. Federally, Australia's Notifiable Data Breaches scheme received 1,205 notifications in 2025, an 8% rise on the prior year and the highest total since the scheme began in 2018, according to the Office of the Australian Information Commissioner.

Across the Tasman, New Zealand's Privacy Commissioner expects notification within 72 hours of an organization identifying a reportable breach, with financial penalties for non-compliance.

The Australian Signals Directorate's Essential Eight framework recommends patching internet-facing systems within 48 hours of a critical vulnerability being identified.

The directorate's most recent Commonwealth Cyber Security Posture report found 22% of federal entities reached Essential Eight Maturity Level 2 across all eight strategies in 2025, up from 15% in 2024.

Mathspace said it is contacting affected individuals directly and has not disclosed whether it has identified the party responsible for the breach.