---
title: "Mathspace breach exposes more than one million… | Firevault"
description: "An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/mathspace-data-breach-one-million-students-2026#webpage",
      "url": "https://fire-vault.com/news/mathspace-data-breach-one-million-students-2026",
      "name": "Mathspace breach exposes more than one million…",
      "description": "An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/news/mathspace-data-breach-one-million-students-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/mathspace-data-breach-one-million-students-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/mathspace-data-breach-one-million-students-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Mathspace breach exposes more than one million students, staff and parents",
          "item": "https://fire-vault.com/news/mathspace-data-breach-one-million-students-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Mathspace breach exposes more than one million students, staff and parents",
      "description": "An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.",
      "url": "https://fire-vault.com/news/mathspace-data-breach-one-million-students-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/mathspace-data-breach-one-million-students-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/mathspace-data-breach-one-million-students-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/mathspace-data-breach-one-million-students-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/images/news/mathspace-data-breach-one-million-students-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-08T11:00:00+00:00",
      "dateModified": "2026-09-08T13:00:42.488665+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/mathspace-data-breach-one-million-students-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 668,
      "keywords": "Mathspace, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "## What happened Mathspace, the online mathematics learning provider used widely by schools in Australia and New Zealand, has confirmed that unauthorised parties accessed an internal reporting system and exported personal data belonging to 1,079,819 students, school staff and parents. The company says the attackers were inside the system between 10 and 27 August 2026, a period during which a secur",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "How many people were affected by the Mathspace data breach?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Mathspace has confirmed that 1,079,819 people across Australia and New Zealand were affected, including students, school staff and parents."
          }
        },
        {
          "@type": "Question",
          "name": "What data was exposed?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "User IDs, usernames, first and last names, email addresses, country, time zone, user type, email-verification status, last-active date, last-login date and date joined. Not every person had all of those fields exposed."
          }
        },
        {
          "@type": "Question",
          "name": "Were passwords or academic records stolen?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Mathspace states that academic records, learning activity, results, assessments, password hashes, authentication tokens, single sign-on credentials and API credentials were not involved."
          }
        },
        {
          "@type": "Question",
          "name": "How did the attackers get in?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "They exploited a security vulnerability in a self-hosted installation of third-party software during a period when the security patch had not been installed, and had access between 10 and 27 August 2026."
          }
        },
        {
          "@type": "Question",
          "name": "What should parents and school staff do now?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Treat unexpected messages with suspicion and verify them independently, never share passwords or verification codes in response to a message, use a unique password for every account, and watch for unusual account activity."
          }
        },
        {
          "@type": "Question",
          "name": "Would Offline Secure Storage have prevented this?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. This was an unpatched connected system, which is answered by asset inventory, patching and segmentation. Offline Secure Storage protects the audit logs and clean data copies that the investigation and notification process depends on, so that evidence cannot be altered or deleted."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Breaking News Updated as information becomes available 

Overview

What happenedWhat was takenWhy the detail mattersWhat this means for schoolsThe Firevault viewSourceMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 8 September 2026 · Breaking 

# Mathspace breach exposes more than one million students, staff and parents

An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmathspace-data-breach-one-million-students-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmathspace-data-breach-one-million-students-2026&text=Mathspace%20breach%20exposes%20more%20than%20one%20million%20students%2C%20staff%20and%20parents%0A%0AAn%20unpatched%20self-hosted%20reporting%20system%20gave%20attackers%20seventeen%20days%20inside%20Mathspace%2C%20exposing%20names%20and%20email%20addresses%20for%201%2C079%2C819%20people%20across%20Australia%20and%20New%20Zealand.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmathspace-data-breach-one-million-students-2026)[](mailto:?subject=Mathspace%20breach%20exposes%20more%20than%20one%20million%20students%2C%20staff%20and%20parents&body=An%20unpatched%20self-hosted%20reporting%20system%20gave%20attackers%20seventeen%20days%20inside%20Mathspace%2C%20exposing%20names%20and%20email%20addresses%20for%201%2C079%2C819%20people%20across%20Australia%20and%20New%20Zealand.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fmathspace-data-breach-one-million-students-2026)

![Illustration of a learning platform laptop with a broken padlock and student account icons streaming out, representing the Mathspace data breach](/images/news/mathspace-data-breach-one-million-students-2026.jpg)

Illustration of a learning platform laptop with a broken padlock and student account icons streaming out, representing the Mathspace data breach

Why it matters

## What this means for organisations holding critical data

An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [What was taken](#section-1)
3.  03 [Why the detail matters](#section-2)
4.  04 [What this means for schools](#section-3)
5.  05 [The Firevault view](#section-4)

**On this page**[What happened](#section-0)[What was taken](#section-1)[Why the detail matters](#section-2)[What this means for schools](#section-3)[The Firevault view](#section-4)

## What happened

Mathspace, the online mathematics learning provider used widely by schools in Australia and New Zealand, has confirmed that unauthorised parties accessed an internal reporting system and exported personal data belonging to 1,079,819 students, school staff and parents.

The company says the attackers were inside the system between 10 and 27 August 2026, a period during which a security patch for its self-hosted installation of third-party software had not been applied. The compromised reporting system has since been taken offline.

## What was taken

The exported records included:

-   User IDs and usernames
-   First names and last names
-   Email addresses
-   Country and time zone
-   User type and email-verification status
-   Last-active date, last-login date and date joined

Not every affected person had every field exposed. Mathspace states that academic records, learning activity, results, assessments, password hashes, authentication tokens, single sign-on credentials and API credentials were not involved, and that the exposed data did not link user accounts to their schools.

The company says it has no evidence so far that the stolen data has been published, shared or sold, and it does not yet know who was responsible. Schools, education departments and cyber security authorities have been notified, and affected individuals are being contacted.

## Why the detail matters

This was not a sophisticated intrusion. It was a known vulnerability in software the organisation hosted itself, left unpatched long enough for an attacker to find it and work quietly for over two weeks.

Steve Hunter, director of engineering for APAC at Arctic Wolf, told the ABC that organisations need a risk-based approach rather than "playing whack-a-mole every time a new vulnerability appears", starting with knowing what systems and software they actually run.

That is the uncomfortable part for anyone responsible for a school estate. A reporting system is rarely on the priority patching list. It is internal, it holds no payment data, and it feels peripheral. It still held the identity of a million children and the adults around them.

## What this means for schools

Education data has a long tail. A pupil's name and email address will still be valid years after they leave, and the accounts that sit behind it will still be reachable. Parents and staff in the same dataset make convincing targets for messages that appear to come from a school.

Three practical points follow from this incident:

1.  **Inventory before defence.** Every self-hosted component, including internal reporting and analytics tools, belongs in the asset register with a named owner and a patch expectation.
2.  **Separate reporting from source data.** Reporting systems accumulate copies. The smaller the copy and the shorter its life, the smaller the loss.
3.  **Protect the record of what happened.** Whether an intrusion lasted seventeen days or seventeen minutes is answered by logs. If those logs sit on the same connected estate as the systems that were breached, they can be altered or deleted.

## The Firevault view

[Offline Secure Storage](/offline-secure-storage)® would not have stopped this intrusion. An unpatched internet-facing reporting tool is a connected-estate problem, and it is answered by inventory, patching and segmentation.

What Offline Secure Storage® does answer is everything that comes after. Notification duties, regulator questions and any later dispute about scope all rest on records that must be exactly as they were written: audit logs, access records and clean copies of the affected datasets. Held offline and immutable, those records cannot be quietly edited by anyone who is still inside the estate, and they survive the moment when live systems are pulled down for investigation.

Mark Fermor, Director and Co-Founder of Firevault, said: "The lesson here is not that Mathspace was careless with encryption. It is that a low-priority internal tool held the identities of a million children. Know what you run, keep the copies small, and keep the evidence of what happened somewhere an attacker cannot reach."

## Source

-   [ABC News: More than 1 million users affected in Mathspace data breach across Australia and New Zealand](https://www.abc.net.au/news/2026-09-07/mathspace-data-breach/107124894)

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.abc.net.au/news/2026-09-07/mathspace-data-breach/107124894)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)[

![Quinn Emanuel and McDermott breached as law firms become the soft route to client data](/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg)

Breach Analysis 

### Quinn Emanuel and McDermott breached as law firms become the soft route to client data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

8 Sept 2026 4 min 







](/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026)[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)[

![Cornelius faces legal investigation after alleged Cl0p cyber attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/cornelius-alleged-clop-ransomware-data-breach-1786684482605.png)

Breach Analysis 

### Cornelius faces legal investigation after alleged Cl0p cyber attack

Cornelius faces legal scrutiny following reports of a Cl0p ransomware breach in August 2026. Claims suggest thousands of gigabytes of corporate data were compromised.

14 Aug 2026 4 min 







](/news/cornelius-alleged-clop-ransomware-data-breach)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)