Mathspace, an online maths learning platform used in schools across Australia and New Zealand, said attackers breached its systems by exploiting a vulnerability in Metabase, an internal reporting tool the company self-hosts.
Mathspace said the attackers gained administrator access as early as 10 August and downloaded data on 27 August. The company confirmed the incident on 3 September.
The breach affected 1,079,819 people across Australia and New Zealand, including students, parents and guardians, teachers and Mathspace staff. Exposed information included names, usernames, email addresses and account details.
Mathspace said no academic records, passwords, authentication tokens or single sign-on credentials were exposed. It also said it had found no evidence that the data had been published or sold.
In comments provided to media, Takanori Nishiyama, senior vice president APAC and country manager for Japan at Keeper Security, said the incident highlighted weaknesses in how organisations secure internal systems.
“The Mathspace breach exemplifies a critical gap in how organisations manage internal infrastructure: when administrative systems sit outside the standard patch management cycle and lack the access controls applied to external facing systems, breaches become an inevitable outcome rather than exceptions,” Nishiyama said. He pointed to Verizon’s 2026 Data Breach Investigations Report, which found exploitation of vulnerabilities became the leading initial access vector for the first time in the report’s 19-year history, accounting for 31% of breaches.
Nishiyama said internal tools such as reporting systems, analytics dashboards and legacy administrative applications are often not treated with the same patching and access-control rigour as internet-facing systems. He cited Keeper Security research stating that 46% of organisations in APAC report significant cloud security gaps, and 32% cite too many tools with poor integration as a weakness that can leave administrative access to internal systems “undetected and unpatched for months”.
He also warned of longer-term risks for children affected by the exposure of personal information. “A child’s data holds long-term value because minors have clean records that few families monitor, and fraud committed in a child’s name can run undetected for years,” Nishiyama said.
Nishiyama said families should treat messages referencing their school or the platform with caution and consider changing reused passwords, setting unique passwords for accounts and enabling multi-factor authentication where available. He also said schools and organisations should ensure internal systems are included in inventory, patch management and access governance practices.

