Schools using education technology provider Mathspace are being urged to check whether they have been contacted about the company’s data breach, verify any notification independently and warn staff, students and families to be alert for convincing phishing or impersonation attempts.
Mathspace began notifying school contacts on 4 September after confirming that unauthorised parties had accessed an internal reporting system and downloaded information relating to students, parents or guardians and school staff.
The company says schools can contact its data-breach response team (data-breach-response@mathspace.co) to confirm whether a notification is genuine and to obtain information about affected users.
Mathspace is also advising users to be cautious of messages that appear to refer accurately to their name, school or the data breach. The company has warned that information exposed in the incident could make impersonation attempts more convincing.
Schools should not assume that a message purporting to come from Mathspace is genuine. Mathspace has specifically advised recipients to start a new email to its published data-breach response address or navigate directly to the Mathspace website rather than following links or opening attachments in a message they are unsure about.
The breach affects 1,079,819 people in Australia and New Zealand, according to Mathspace, including students, parents or guardians, teachers and Mathspace staff. Former or inactive users may also be affected.
The information accessed included names, email addresses, usernames, user IDs, country, time zone and account activity information.
Mathspace says passwords, single sign-on tokens, authentication credentials, academic records, learning activities and assessment results were not exposed.
The company said unauthorised access began on 10 August and information was downloaded on 27 August. Mathspace confirmed the breach on 3 September and began notifying schools the following day. Direct notifications to affected individuals began on 6 September.
The incident involved an unpatched, self-hosted installation of Metabase used by Mathspace for internal reporting. Mathspace said a critical Metabase security advisory issued on 6 August was not identified and escalated through its internal vulnerability-notification process.
The company subsequently patched the system but said it did not complete additional compromise checks recommended for potentially affected systems. A later review of historical logs identified the unauthorised access.
Mathspace said it has since revoked API keys, disabled database access accounts and changed passwords for its Metabase Cloud SQL databases.
It has reported the incident to the Office of the Australian Information Commissioner, the Australian Signals Directorate’s Australian Cyber Security Centre and relevant New Zealand authorities. It has also notified Australian state and territory education departments.
The NSW Department of Education has confirmed that six NSW public schools have been notified by Mathspace about the breach. The department said it would work with Mathspace and communicate with affected school communities. Around 85 NSW public schools use the platform.
Mathspace says there is currently no evidence that the stolen information has been published, distributed, sold or otherwise misused.
The company has advised affected users to remain vigilant for suspicious communications and said it does not know who was responsible for the breach.
For schools, the immediate priority is to establish whether their users are affected, verify communications directly with Mathspace and ensure staff and families understand that information from the breach could potentially be used to make fraudulent messages appear legitimate.

