Mathspace confirmed on 3 September 2026 that attackers downloaded account data on 1,079,819 people in Australia and New Zealand after gaining administrator access to a self-hosted Metabase reporting system. The company published its primary notice on the Mathspace blog; BleepingComputer covered the disclosure. Canonical BreachHistory record: https://breachhistory.com/mathspace/mathspace-metabase2026.
This is not a password dump and it is not a grades leak. It is a large directory of students, parents or guardians, school staff, and Mathspace employees — names, email addresses, and account metadata — stolen through an unpatched Metabase vulnerability that the company later admitted its process missed.
For anyone searching Mathspace data breach or Mathspace breach 2026, the short version is: the incident is company-confirmed, the headcount is attested, Australia and New Zealand are in scope, and phishing risk is the main everyday threat now that the data is out.
What happened: Mathspace Metabase timeline
Metabase published a critical security advisory and patched builds on 6 August 2026. Mathspace runs a self-hosted Metabase instance for internal reporting. Its vulnerability-notification process did not escalate that first advisory.
Unauthorised access began on 10 August 2026, Australian Eastern Standard Time. On 27 August, the attacker downloaded information from Mathspace's Australian reporting database. Mathspace applied a Metabase update on 29 August after a later vendor notice finally got attention — still without completing the extra compromise checks Metabase recommends for systems that may already have been hit.
Historical log review on 3 September confirmed the earlier access window. That is when Mathspace closed its investigation of scope and published the census: 1,079,819 affected people across students, parents or guardians, school staff, and Mathspace staff. Only Australia and New Zealand records were in the exported set.
School contacts started receiving notifications on 4 September. Individual notices began on 6 September, earlier than the date schools had been told to expect. Regulators were notified the same day schools were contacted: Australia's OAIC and ASD's ACSC, New Zealand's Privacy Commissioner and National Cyber Security Centre, plus Australian state and territory education departments.
To be clear: Mathspace says it has no evidence so far that the stolen file has been published, sold, or otherwise misused. The attacker remains unknown in the company notice. Trade press has linked the wider August Metabase wave to groups including ShinyHunters, but Mathspace itself has not named a group — so treat actor attribution as context, not a Mathspace claim.
Founded in Sydney in 2010, Mathspace is a familiar name in Australian and New Zealand maths classrooms and is also used by schools further afield. BleepingComputer noted company figures from 2023 citing thousands of schools in Australia and abroad. The September disclosure is notable because the stolen slice was limited to AU/NZ reporting data even though the product footprint is wider — a reminder that breach scope follows which warehouse a compromised BI tool can query, not which countries appear on a marketing map.
What was exposed in the Mathspace data breach
The exported reporting rows included:
- User ID (internal Mathspace identifiers, including student account IDs)
- Username
- First name and last name
- Email address
- Country and time zone
- User type
- Email-verification status
- Last-active date, last-login date, and date joined
Not every field was populated for every person. Still, this is more than a bare mailing list. A username plus last-login date plus a school-looking email domain is enough raw material for targeted phishing that sounds like it came from Mathspace, a year adviser, or a parent portal.
Mathspace's earlier school messaging understated the account-detail fields. The September 6 update is explicit that user IDs and activity dates travelled with the names and email addresses. That correction matters for schools drafting parent letters: if you only warned about names and emails, update the community so they understand activity metadata can make social engineering sharper.
User type is an underrated field. Knowing whether a row is a student, guardian, teacher, or staff account helps an attacker pick the right script — fee panic for parents, homework urgency for students, roster admin for teachers.
What was not exposed
Equally important for families and IT admins:
- Passwords and password hashes
- SSO tokens and other authentication credentials
- API credentials
- Academic records, learning activities, results, and assessment data
Mathspace is not requiring a product password reset because of this incident. The company also says the export did not include a direct school-to-account linkage table. Caveat: if a school uses an identifiable email domain, an attacker can still infer affiliation from the address alone.
So if you are asking whether 1 million students lost maths scores or login secrets — no, not according to the verified notice. If you are asking whether a million contact records left Mathspace's reporting warehouse — yes.
That boundary should shape school crisis messaging. Do not tell families "nothing sensitive was taken" — contact data on minors is sensitive. Do tell them grades and passwords were not in the download Mathspace described, so a forced Mathspace password reset is not the company's remediation path.
How the attack worked: unpatched Metabase admin access
Mathspace's own language is blunt. Attackers exploited a security vulnerability in the self-hosted Metabase install. The flaw let them obtain administrator access without a legitimate login.
That pattern matches the August 2026 Metabase campaign tracked across multiple BreachHistory rows. Critical Metabase issues in that window allowed remote takeover of vulnerable instances, then abuse of whatever databases the BI tool could reach. Once you are Metabase admin, you are not "just" reading a dashboard — you are sitting on the credentials and query paths wired into Snowflake or other warehouses.
Mathspace's containment steps on 3 September show what was connected. The company took Metabase offline, revoked all Metabase API keys, disabled Metabase database access accounts in Australian and US Snowflake environments, and changed passwords for Metabase Cloud SQL databases. It also copied the Metabase application database and exported access logs for forensics. Metabase remains offline while recovery checks continue.
The US Snowflake disablement is worth a beat even though the stolen people were AU/NZ-only. Connected warehouses can span regions; cutting both Australian and US database access accounts is how you stop a compromised BI plane from becoming a pivot into other reporting slices while forensics finishes.
The operational failure is familiar: a critical vendor advisory landed on 6 August; the patch landed on 29 August; the download happened on 27 August. Two days of unpatched exposure after the first advisory would have been bad. Nineteen days of silent admin access before the Australian database export is worse. Mathspace says it is investigating why the first advisory was not escalated and why post-patch compromise checks were skipped, and is changing both processes.
Patching without hunting is a recurring miss in the Metabase wave. If an unpatched vulnerability was already live in the wild, installing the fixed build closes the front door but does not eject an attacker who already created sessions, API keys, or shadow admin users. Mathspace's notice effectively admits that second step arrived late.
Who is at risk after the Mathspace breach 2026
Students in Australia and New Zealand
If you used Mathspace at school — even years ago — an inactive account can still sit in a reporting database. Leaving a school does not automatically remove you from scope. Expect notices that name you accurately. Treat unexpected password-reset mail, "verify your Maths account" links, and DMs that cite your real username as suspicious until you verify out of band.
Students who are unsure should loop in a parent, guardian, or teacher rather than clicking through a scary message alone.
Parents and guardians
Parent and guardian records were in the same export. That means family email addresses are in play, not only student ones. Watch for school-fee scams, fake consent forms, and messages that claim Mathspace needs a credit card or government ID to "secure your child's account." Mathspace's verified channel for questions is [email protected] — start a new email; do not reply to a random forward.
Confirm school portal messages through the school's known website or phone tree — not through the same week's panic emails.
School staff and administrators
Teachers and school contacts are high-value phishing targets because they can unlock wider student communications. School administrators can email the same breach-response address to request counts of affected students, staff, and parents for their school, or to arrange secure sharing of record details. Ask for a post-incident update if you need language for your own community letters.
IT teams should brief help desks: callers who already know a staff member's Mathspace username or last-login window may still be fraudsters.
Mathspace staff
Employee records were affected too. Internal phishing that references this exact incident is likely. Rotate any reused personal passwords, and treat unexpected MFA prompts as hostile until confirmed through known channels.
Users outside AU/NZ
Mathspace also serves schools in other countries, including the United States and United Kingdom. The company says only Australia and New Zealand people were in this download. That boundary is company-attested — still worth watching if a follow-up notice expands scope, but do not invent US/UK impact that Mathspace has not claimed.
Edtech and Metabase campaign context
August–September 2026 turned self-hosted Metabase into a recurring headline. Mathspace is the largest edtech census so far in that cluster: more than 1 million students, parents, and staff in one Australian reporting pull.
Related confirmed paths in the same campaign window include fulfillment and consumer brands hit through Metabase-connected systems. ShipMonk disclosed a Metabase vulnerability path that cascaded into merchant notices, including Trezor customer shipping data — impact that later expanded in Trezor's follow-up notices. Separate product victims such as Framework and Tally also published Metabase-driven theft after administrator takeover of analytics instances.
The common lesson is not "never use BI tools." It is that an internet-reachable Metabase admin plane with warehouse credentials is production root access dressed as reporting. Patch SLAs that treat optional analytics as low priority are how you end up notifying a million families.
Edtech specifically concentrates minors' contact data, parent emails, and school trust. Even without grades or passwords, a clean directory of school-aged users is useful for social engineering against households that already trust education brands. The harm model skews toward long-tail household phishing rather than physical stalking — still real, just different.
Security teams in schools and edtech vendors should inventory every analytics connector that can SELECT from student identity tables. If Metabase, Looker, Superset, or a home-grown dashboard can reach production-like identity data, treat its patching and network exposure with the same seriousness as the student information system itself.
What Mathspace said and did
CTO Alvin Savoy's notice apologises, owns the missed advisory, and lists containment. Beyond taking Metabase offline and cutting Snowflake access, the company preserved forensic artefacts and began coordinated school-then-individual notification. Regulators in both Australia and New Zealand were told on 4 September.
Mathspace is not requiring customer password resets. It is telling people to change passwords they reused elsewhere, watch account activity, and verify messages independently. Schools wanting forensic detail can request an incident update through the breach-response mailbox.
Remaining work, per the company: finish individual notifications, answer school record requests, complete recovery checks before Metabase returns, and redesign advisory escalation plus post-disclosure compromise testing. That last item — proving an attacker is gone after you patch — is the part many organisations skip under time pressure, and Mathspace has put it on the public record as a process gap.
Was I affected — and what to do after
You are most likely in scope if you are a student, parent/guardian, school staff member, or Mathspace employee with an Australia or New Zealand account footprint that still lived in the reporting database as of late August 2026. Former and inactive users can still be included.
There is no public self-serve lookup tool described in the notice. Confirmation paths are school admin requests and direct mail to [email protected]. Navigate to Mathspace's site yourself rather than trusting links inside an unexpected message that merely mentions the Mathspace data breach.
Practical guidance on what to do after a directory-style breach like this:
- Assume your name and email are known to the attacker if you are AU/NZ Mathspace-related. Treat clever phishing as the primary risk, not password stuffing against Mathspace itself.
- Verify school or Mathspace messages out of band. Call the school office number you already have, or open a fresh email to [email protected]. Do not open surprise attachments about "affected student lists."
- Never hand over passwords, SSO codes, or MFA tokens in response to a cold message — even one that correctly spells your child's name and school.
- Unique passwords everywhere you reused credentials. Mathspace passwords were not stolen, but reuse habits still get people burned when other services leak.
- Watch for password-reset spam and unexpected account-detail changes on email, school portals, and banking apps tied to the same address.
- Parents: brief kids. Explain that scammers may pretend to be Mathspace or a teacher and that the right move is to ask an adult before clicking.
- School IT: harden help-desk scripts and warn staff that accurate usernames from this incident do not prove a caller is legitimate.
- Report suspicious mail to [email protected] and to your school's usual security contact.
- Ignore "download the Mathspace leak" forums. Archives may be malware or recycled dumps. Mathspace says it has no evidence of public sale so far.
- Operators of self-hosted Metabase: confirm you are on a patched build, remove public ingress if reporting does not need it, rotate every database secret Metabase can reach, and hunt for unexpected admin users or API keys created since early August 2026.
Phishing patterns to expect
With names, emails, user types, and activity dates in hand, attackers can write sharper lures than generic "your account is locked" spam:
- "Mathspace security: confirm your parent email after the September breach" with a fake login page.
- "Your school needs updated guardian consent — open the attached PDF."
- "We noticed last login from an unknown device on [date that matches the stolen field]."
- SMS claiming a Maths homework portal fee is unpaid and linking to a payment page.
Legitimate remediation does not arrive as a random file share or a Telegram "delete my data" broker. Stick to school communications you already trust and the mathspace.co breach-response address.
Why the count matters for Australia New Zealand schools
1,079,819 is not a dark-web marketing number. It is Mathspace's closed-scope census after investigation. That makes the Mathspace breach 2026 one of the larger verified education-sector contact exposures of the year in Australia and New Zealand combined.
Schools will feel operational pressure: parent questions, media calls, and the need to separate real Mathspace notices from copycat phishing. Mathspace contacted schools first specifically so communities could coordinate messaging — then accelerated individual notices when schools asked for speed.
For privacy teams, the field list is classic "account metadata without credentials." It still triggers notification duties and still fuels fraud. Do not downplay it because grades stayed indoors. OAIC and New Zealand privacy processes will run on their own clocks; families should not wait for a regulator headline before ignoring suspicious mail.
Canonical record and sources
Full catalog entry: /mathspace/mathspace-metabase2026 (absolute: https://breachhistory.com/mathspace/mathspace-metabase2026). Company-confirmed; records affected 1,079,819; root cause framed as an unpatched Metabase vulnerability on self-hosted internal reporting.
Primary sources: Mathspace data-breach FAQ (updated 6 September 2026); BleepingComputer, 7 September 2026. Related Metabase-wave context: ShipMonk / Trezor fulfillment notices and other August 2026 Metabase victim disclosures covered in trade press.
Searchers landing here for Mathspace data breach, Metabase unpatched vulnerability, 1 million students email addresses Australia New Zealand, or what to do after the Mathspace breach should treat the company blog as the living FAQ and this BreachHistory page as the durable incident summary. If Mathspace later expands the census or confirms misuse, the catalog row will be the place to check first.