Mathspace Data Breach: What Parents Should Do

08.09.26 09:11 - By Shaun Barnett

Your child's maths app was breached. This is the rare one where you probably don't need to do much.

If you have a child at an Australian or New Zealand school, there is a reasonable chance you got an email over the weekend from a company you may never have chosen, about an app you may never have used, telling you your family's details were taken.

The company is Mathspace, an online maths platform used in schools across both countries. On Sunday 6 September it began contacting affected people. The number is 1,079,819 — students, parents and guardians, school staff, and Mathspace's own employees, across Australia and New Zealand combined.

That is a very large number, and it will be the number in every headline this week.

Here is the part the headlines will bury: what was actually taken from each of those people is small. Not nothing. Small. And knowing the difference is the entire skill.

We published a guide yesterday about blocking your driver's licence after a breach. This is the companion piece, and it argues almost the opposite — because this is a different kind of breach, and treating every breach the same is how people burn out and stop responding to the ones that matter.

What was taken

Mathspace has published a detailed notice and updated it as the investigation closed. Per that notice, the exported records could include:

  • User ID and username
  • First name and last name
  • Email address
  • Country and time zone
  • User type (student, parent or guardian, teacher, staff)
  • Email verification status
  • Last active date, last login date, and date joined

Not every field was present for every person.

What was not taken

This list matters more than the one above, and it is unusually clear-cut:

-No academic or learning data. No results, no assessment records, no work your child submitted.
-No passwords. Not even hashed ones.
-No single sign-on tokens, authentication tokens or API credentials.
-No financial information. Mathspace's internal reporting system did not hold any.

Mathspace is not forcing a password reset, because customer credentials were not in the exposed data. It has also said there is no evidence so far that the information has been published, shared or sold, and no group has claimed responsibility.

Hold both halves of that lightly. "No evidence so far" is an honest statement about the present, not a promise about November.

Why "a million people" doesn't tell you how bad yours is

Two breaches can affect a million people each and be nothing alike.

When Origin Energy disclosed in July, roughly 900,000 people had identity and account data exposed — the kind of information that can be assembled into a credible attempt to be you. That is a breach where replacing a document is a proportionate response.

This one is a list of names, email addresses and account metadata. On its own, it does not let anyone open an account in your name, drain anything, or log in as you.

The headline number tells you the size of the company's problem. It tells you almost nothing about the size of yours. Those are two different measurements and they get printed as one.

If you have spent the last few years watching breach notifications arrive and feeling steadily worse about each one, this is the useful thing to take from today: the notifications are not interchangeable. You are allowed to read one and conclude that it is small.

The one real risk, and it is worth naming precisely

Here is what a list like this is actually good for.

Somebody now holds a verified set of email addresses, each one tagged with a real name, a role — *this is a parent, this is a student, this is a teacher* — and, in many cases, evidence that the address is live and recently used.

That is a phishing list of unusual quality. Not because any single field is sensitive, but because the tagging removes the guesswork. A message can now open with your actual name, reference your actual child, and mention this actual breach.

Mathspace's own guidance says as much: be cautious even when a message uses your name or refers accurately to your school or to this incident.

So the realistic scenario over the next few months is not fraud. It is a well-written email that appears to come from Mathspace, from your child's school, or from a support service, asking you to sign in somewhere or open something.

What to actually do

Four things. Most people will be finished in ten minutes.

1. If you reused your Mathspace password anywhere, change it there. Your password wasn't taken — but if it was one you also use for email or banking, this is a reasonable prompt to fix that regardless. Different password for every account, kept in a password manager or written in a notebook at home. Both are fine. Reuse is the problem, not the storage.

2. Treat every message about this breach as unverified, including ones that look official. If an email asks you to click through and sign in, don't. Go to the site yourself, the way you normally would. This applies to messages that appear to come from the school as much as from Mathspace.

3. Talk to your child, briefly and calmly. Their email address is on this list too. The message is simple: someone might send you an email that knows your name and your school, and that doesn't make it real. Mathspace's own notice tells students to ask a parent, guardian or teacher if they're unsure — which is exactly right, and worth saying out loud at home so they know they can.

4. Turn on two-factor authentication for your email account if it isn't already, using an authenticator app rather than SMS. Not because of this breach specifically. Because your email is the recovery route for everything else you own, and this week you happen to be thinking about it.

What you don't need to do

This section is deliberate, and it is the more useful half.

You don't need to replace your driver's licence. No identity documents were involved. Nothing here goes near the Document Verification Service.

You don't need a credit ban on the strength of this breach alone. A credit ban is free and it is genuinely the right call after an identity-document exposure. This isn't one.

You don't need to reset your Mathspace password, though you can if it makes you feel better and there's no harm in it.

You don't need to sit with a low-grade dread about this for the next six months. The honest ceiling on this exposure is targeted phishing. Phishing is defeated by not clicking, and you already know how to not click.

If you are also in Origin, Qantas, or another breach that took identity documents, then the licence and credit-ban advice applies — but it applies because of those, not because of this one.

The part that's worth being annoyed about

Mathspace has been unusually transparent, and it deserves credit for that. The notice is specific, it names what wasn't taken as clearly as what was, and it was updated as the picture firmed up. That is better disclosure than most Australian companies manage.

But the timeline is worth reading closely, because there's a lesson in it that isn't only about Mathspace.

  • 6 August — a security advisory is published for Metabase, the internal reporting tool Mathspace ran on its own servers.
  • 10 August — unauthorised access begins.
  • 27 August — data is downloaded from the Australian reporting database.
  • 3 September — a review of historical access logs confirms the breach.
  • 4 September — regulators in both countries are notified.
  • 6 September — affected people start being told.

Mathspace has said its internal process for tracking security advisories didn't catch the August one. That's the first gap.

The second is sharper, and it's the one worth carrying. Mathspace did eventually apply the update — but by its own account it "did not complete the additional compromise checks" recommended for systems that may already have been reached.

The hole was closed. Nobody looked for footprints. Seventeen days passed between the first unauthorised access and the download, and another week before anyone reviewed the logs that showed it — twenty-four days in all.

That's an organisational failure at scale, but it is the same mistake individuals make constantly, in miniature. You get a breach notification, you change the password, you feel finished. Changing the password closes the door. It does nothing about what was carried out before you changed it, and it doesn't tell you what that was.

Fixing is not the same as checking. That distinction is most of what separates people who recover quickly from people who find out eighteen months later.

You didn't choose this app

Worth saying plainly, because it's the part that produces the most misplaced guilt.

Almost nobody on that list of a million went shopping for a maths platform. A school did. A department did. Your child was enrolled and an account was created, and the terms were agreed to somewhere well above your head.

This is now the pattern rather than the exception in Australian education. Over the past year, breach indexes have logged incidents touching the Victorian Department of Education, the Queensland Department of Education via a third-party cloud provider, and the Canvas learning platform used across schools and universities. Different companies, different causes, same structural fact: the software holding your child's details was selected by an institution, and you had no realistic way to decline.

You cannot be a careful consumer of a vendor you never chose. Which is precisely why the response has to be about what you do afterwards, not about what you should have done differently.

The short version

A million-plus people had their name and email address taken from a school maths platform. No passwords, no schoolwork, no identity documents. Expect convincing phishing that knows your child's name. Change reused passwords, don't click through emails about this, tell your kid, and then get on with your week.

Not every breach is the big one. Knowing which is which is the whole skill — and it's the difference between staying alert for years and going numb by Christmas.

SelfCybr helps Australian individuals and families see what's exposed, fix it, and learn how to stay ahead of it. No jargon, no shame, no data sold — ever. Australian-owned, Australian-hosted.

Sources and further reading

THE BREACH

  • Mathspace — "Mathspace data breach: what happened and what affected users should know", notice last updated 6 September 2026 (primary source) https://blog.mathspace.co/mathspace-data-breach-what-happened-and-what-affected-users-should-know/
  • ABC News — "More than 1 million users affected in Mathspace data breach across Australia and New Zealand", 7 September 2026 https://www.abc.net.au/news/2026-09-07/mathspace-data-breach/107124894
  • Cyber Daily — "Breached! Tutoring platform Mathspace says 1m-plus Aussies implicated by data breach", 7 September 2026 https://www.cyberdaily.au/security/14148-breached-tutoring-platform-mathspace-says-1m-plus-aussies-implicated-by-data-breach
  • The Cyber Express — "Mathspace data breach", 7 September 2026 https://thecyberexpress.com/mathspace-data-breach/
  • DataBreaches.net — "Mathspace breach impacts more than 1 million users in Australia, NZ", 7 September 2026 https://databreaches.net/2026/09/07/mathspace-breach-impacts-more-than-1-million-users-in-australia-nz/

FOR COMPARISON
  • ABC News — "Origin Energy believes 900,000 customers' data accessed in breach", 28 July 2026 https://www.abc.net.au/news/2026-07-28/origin-energy-data-breach-900k-customers-impacted/106961804

PRIVACY REFORM
  • Attorney-General's Department — Privacy reform consultation (Privacy Amendment (Personal Data Protection) Bill 2026 exposure draft; submissions close 18 September 2026) https://consultations.ag.gov.au/rights-and-protections/privacy-reform/
  • iTnews — "Privacy Act overhaul to tighten 72-hour breach reporting deadline", 2 September 2026 https://www.itnews.com.au/news/privacy-act-overhaul-to-tighten-72-hour-breach-reporting-deadline-628568

WHERE TO GET HELP
  • IDCARE — idcare.org, or 1800 595 160 https://www.idcare.org/
  • Scamwatch — report a scam https://www.scamwatch.gov.au/report-a-scam
  • ReportCyber / Australian Cyber Security Centre — cyber.gov.au https://www.cyber.gov.au/
  • OAIC — Data breaches https://www.oaic.gov.au/privacy/data-breaches
Shaun Barnett

Shaun Barnett