Mathspace Data Breach Exposes Personal Information of Over One Million Users in Australia and New Zealand
Online mathematics education provider Mathspace has confirmed a major cyberattack that compromised the personal data of 1,079,819 students, parents, guardians, and teachers across Australia and New Zealand. The breach occurred between August 10 and August 27, 2024, after a security patch was not installed on an internal reporting system.
How the Breach Happened
In a blog post authored by Chief Technical Officer Alvin Savoy, Mathspace disclosed that “unauthorised parties” were able to access an internal reporting system during the 17-day window. The vulnerability stemmed from an unpatched security update, leaving the system exposed to external actors.
What Data Was Stolen
The attackers accessed a range of account details, though not every victim had all fields compromised. Exposed data includes:
- User ID
- Username
- First and last name
- Email address
- Country
- Time zone
- User type (student, teacher, parent, etc.)
- Email-verification status
- Last-active date
- Last-login date
- Date joined
Mathspace emphasized that no academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed.
Regarding school affiliations, the company stated: “The exposed data did not include records linking user accounts to their schools,” the post read. “However, for schools with identifiable email domains, we understand this may be possible.”
Identity of Attackers Unknown; No Evidence of Data Publication
The perpetrators of the cyberattack remain unidentified. Mathspace reports no evidence so far that the stolen data has been published, distributed, or sold on the dark web or elsewhere.
Phishing and Impersonation Risks
Mathspace warned that the stolen information—particularly names and email addresses—could fuel convincing impersonation attempts. “Names, email addresses and account details can make impersonation attempts more convincing,” Mathspace said. “Someone may use them to send a message that appears to come from Mathspace, your school or another organisation you know.”
The company urged vigilance:
- Check unexpected messages independently.
- Do not share passwords or verification codes in response to unsolicited messages.
- If unsure, contact the organisation directly using official website contact details—do not hit “reply” on a suspicious message.
- “Watch for unusual account activity. Pay attention to unexpected password-reset emails or changes to your account details,” Mathspace said.
- Anyone using the same password for Mathspace and other accounts should immediately update those credentials to unique, strong passwords.
Response and Notification Efforts
Mathspace has notified affected schools, cyber authorities, and education departments in both Australia and New Zealand. The company is now working to contact impacted individuals directly.
The compromised internal reporting service has been taken offline. Users who wish to verify whether their data was affected can email [email protected] or use the support channels on the Mathspace website.
Company Apology and Commitment
“We’re truly sorry this happened and are taking steps to prevent similar breaches in the future,” the blog post read. “Protecting the information entrusted to us by students, families and schools is our responsibility.”

