Mathspace breach exposes more than one million students, staff and parents
An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

Why it matters
What this means for organisations holding critical data
An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.
What happened
Mathspace, the online mathematics learning provider used widely by schools in Australia and New Zealand, has confirmed that unauthorised parties accessed an internal reporting system and exported personal data belonging to 1,079,819 students, school staff and parents.
The company says the attackers were inside the system between 10 and 27 August 2026, a period during which a security patch for its self-hosted installation of third-party software had not been applied. The compromised reporting system has since been taken offline.
What was taken
The exported records included:
- User IDs and usernames
- First names and last names
- Email addresses
- Country and time zone
- User type and email-verification status
- Last-active date, last-login date and date joined
Not every affected person had every field exposed. Mathspace states that academic records, learning activity, results, assessments, password hashes, authentication tokens, single sign-on credentials and API credentials were not involved, and that the exposed data did not link user accounts to their schools.
The company says it has no evidence so far that the stolen data has been published, shared or sold, and it does not yet know who was responsible. Schools, education departments and cyber security authorities have been notified, and affected individuals are being contacted.
Why the detail matters
This was not a sophisticated intrusion. It was a known vulnerability in software the organisation hosted itself, left unpatched long enough for an attacker to find it and work quietly for over two weeks.
Steve Hunter, director of engineering for APAC at Arctic Wolf, told the ABC that organisations need a risk-based approach rather than "playing whack-a-mole every time a new vulnerability appears", starting with knowing what systems and software they actually run.
That is the uncomfortable part for anyone responsible for a school estate. A reporting system is rarely on the priority patching list. It is internal, it holds no payment data, and it feels peripheral. It still held the identity of a million children and the adults around them.
What this means for schools
Education data has a long tail. A pupil's name and email address will still be valid years after they leave, and the accounts that sit behind it will still be reachable. Parents and staff in the same dataset make convincing targets for messages that appear to come from a school.
Three practical points follow from this incident:
- Inventory before defence. Every self-hosted component, including internal reporting and analytics tools, belongs in the asset register with a named owner and a patch expectation.
- Separate reporting from source data. Reporting systems accumulate copies. The smaller the copy and the shorter its life, the smaller the loss.
- Protect the record of what happened. Whether an intrusion lasted seventeen days or seventeen minutes is answered by logs. If those logs sit on the same connected estate as the systems that were breached, they can be altered or deleted.
The Firevault view
Offline Secure Storage® would not have stopped this intrusion. An unpatched internet-facing reporting tool is a connected-estate problem, and it is answered by inventory, patching and segmentation.
What Offline Secure Storage® does answer is everything that comes after. Notification duties, regulator questions and any later dispute about scope all rest on records that must be exactly as they were written: audit logs, access records and clean copies of the affected datasets. Held offline and immutable, those records cannot be quietly edited by anyone who is still inside the estate, and they survive the moment when live systems are pulled down for investigation.
Mark Fermor, Director and Co-Founder of Firevault, said: "The lesson here is not that Mathspace was careless with encryption. It is that a low-priority internal tool held the identities of a million children. Know what you run, keep the copies small, and keep the evidence of what happened somewhere an attacker cannot reach."
Source
Sources
Where this reporting comes from
How Firevault would handle this
A recovery copy an attacker cannot reach
Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.






