Skip to content

Around the World

Mathspace Data Breach Exposes Data of Over 1 Million Students, Adults

Mathspace Data Breach Exposes Personal Information of Over One Million Users in Australia and New Zealand Online mathematics education provider Mathspace has confirmed a major cyberattack that compromised the personal...

Mathspace Data Breach Exposes Personal Information of Over One Million Users in Australia and New Zealand

Online mathematics education provider Mathspace has confirmed a major cyberattack that compromised the personal data of 1,079,819 students, parents, guardians, and teachers across Australia and New Zealand. The breach occurred between August 10 and August 27, 2024, after a security patch was not installed on an internal reporting system.

How the Breach Happened

In a blog post authored by Chief Technical Officer Alvin Savoy, Mathspace disclosed that “unauthorised parties” were able to access an internal reporting system during the 17-day window. The vulnerability stemmed from an unpatched security update, leaving the system exposed to external actors.

What Data Was Stolen

The attackers accessed a range of account details, though not every victim had all fields compromised. Exposed data includes:

  • User ID
  • Username
  • First and last name
  • Email address
  • Country
  • Time zone
  • User type (student, teacher, parent, etc.)
  • Email-verification status
  • Last-active date
  • Last-login date
  • Date joined

Mathspace emphasized that no academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed.

Regarding school affiliations, the company stated: “The exposed data did not include records linking user accounts to their schools,” the post read. “However, for schools with identifiable email domains, we understand this may be possible.”

Identity of Attackers Unknown; No Evidence of Data Publication

The perpetrators of the cyberattack remain unidentified. Mathspace reports no evidence so far that the stolen data has been published, distributed, or sold on the dark web or elsewhere.

Phishing and Impersonation Risks

Mathspace warned that the stolen information—particularly names and email addresses—could fuel convincing impersonation attempts. “Names, email addresses and account details can make impersonation attempts more convincing,” Mathspace said. “Someone may use them to send a message that appears to come from Mathspace, your school or another organisation you know.”

The company urged vigilance:

  • Check unexpected messages independently.
  • Do not share passwords or verification codes in response to unsolicited messages.
  • If unsure, contact the organisation directly using official website contact details—do not hit “reply” on a suspicious message.
  • “Watch for unusual account activity. Pay attention to unexpected password-reset emails or changes to your account details,” Mathspace said.
  • Anyone using the same password for Mathspace and other accounts should immediately update those credentials to unique, strong passwords.

Response and Notification Efforts

Mathspace has notified affected schools, cyber authorities, and education departments in both Australia and New Zealand. The company is now working to contact impacted individuals directly.

The compromised internal reporting service has been taken offline. Users who wish to verify whether their data was affected can email [email protected] or use the support channels on the Mathspace website.

Company Apology and Commitment

“We’re truly sorry this happened and are taking steps to prevent similar breaches in the future,” the blog post read. “Protecting the information entrusted to us by students, families and schools is our responsibility.”

DN19 Newsroom

Penulis

Staff writer at DailyNews19 covering buzz, celebs and coins. Passionate about viral culture and the stories behind the headlines.