Skip to content
Back to Blog
medium severity September 07, 2026 · 4 min read

Mathspace data breach: 1 million students, parents and staff in Australia and NZ

If you received a notice from Mathspace, here’s what the filing says was exposed, and what to do about it.

Mathspace has confirmed that names, emails and account details for 1,079,819 students, parents and school staff in Australia and New Zealand were downloaded from an internal system in August 2026. Passwords and academic records were not taken. The company is notifying affected people and has reported the incident to Australian and New Zealand authorities.

Mathspace data breach: 1 million students, parents and staff in Australia and NZ

On 3 September 2026, Mathspace confirmed that unauthorised people had got into an internal reporting system and downloaded information on 1,079,819 students, parents or guardians, and school staff. Only people in Australia and New Zealand were affected. The unauthorised access began on 10 August 2026, and information was downloaded from the Australian reporting database on 27 August. Attackers used a security flaw in reporting software Mathspace ran in-house; a fix had been published on 6 August, and Mathspace applied it on 29 August.

According to Mathspace, the download included first and last name, username, email address, user ID, country, time zone, whether the person was a student, parent or staff member, whether the email was verified, and the dates the account was created, last used and last logged in. Not every field was present for every person. Academic records, results, learning activity, passwords and other login credentials were not exposed. Mathspace says it has no evidence the information has been published, sold or otherwise misused, and it does not know who the attacker was. The system was taken offline on 3 September. Schools were contacted from 4 September and individuals from 6 September.

The missing piece is not grades. It is a labelled list of families.

Coverage of this incident will lean on what was not taken: no passwords, no test scores, no classwork, and no field in the file that names a student’s school. That is all true, and it matters. Nobody can log into a Mathspace account with this data, and nobody received a copy of a child’s results.

What that framing skips is what the file actually is. It is names and email addresses, tagged as student, parent or staff, with a record of when the account was last used. For a parent, that can mean a stranger now has a child’s name sitting next to an adult’s email, marked as a household that uses a school maths platform. For school staff, it is a name and email marked as education staff. Mathspace has said the export did not include a record linking each account to a school, though an email address that obviously belongs to a school could still give that away.

That is a different problem from a stolen password. It is closer to someone holding a directory of households with school-age children and a way to write to them. The honest near-term risk is not a stranger changing marks or getting into the account. It is a convincing message that looks as if it comes from Mathspace or from school, using a real name, at a real email, at a moment when this breach is already in the news.

What to actually expect

  • If you or your child used Mathspace in Australia or New Zealand, the company says it is notifying people directly, and schools were told first. That notice — or one from the school — is the way to know you were included. A clean result on a public breach website does not mean you were left out, and there is no reliable public lookup for this incident.
  • Watch for emails or messages that use a real name, mention Mathspace or a school account, and ask you to click, log in, confirm details or pay. The fields that were taken are enough to make that kind of contact look personal.
  • Mathspace says it has no evidence the data has been posted, sold or passed on. That can change later, but as of the company’s own statement it is not sitting in public.
  • You do not need to change a Mathspace password because of this incident. Passwords were not in the download, and changing one will not pull names and emails back.

What you can and cannot fix

The names, email addresses, usernames and account details that were copied cannot be undone. If that information was in the download, it is out. Taking the system offline stops further access to that system; it does not un-copy a file that already left. No one can credibly promise to remove it.

What still helps, in order:

  • Treat unexpected contact about this breach, a Mathspace account, or a child’s school login as untrusted unless you reached the school or Mathspace yourself through a channel you already use. Do not click a link in those messages to “verify” anything.
  • If a child in the household reads their own email, tell them that a message using their real name or mentioning Mathspace is not automatically genuine, and that they should show you anything that asks them to log in or send more information.
  • A bare leaked record becomes more useful to a scammer when it can be joined to people-search listings that add relatives, phone numbers, employers and previous addresses. Those listings, unlike the Mathspace file, can often be removed. Reducing that extra public footprint is the lever that is still in your hands.

Report details & sourcing

Severity Medium contact details only, none of them permanent
Disclosed September 07, 2026
Last reviewed September 7, 2026
Affected Unconfirmed
Data exposed Full namesEmail addressesUsernamesUser IDsUser typesCountryTime zonesEmail-verification status +3 more
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email