Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than one million students, staff, and parents after breaching its Metabase internal reporting system. The incident, discovered recently, exposed personal information stored within the platform used by educational institutions globally. Mathspace, founded in Sydney in 2010, provides adaptive mathematics learning tools to schools and individual learners.
The breach occurred through unauthorized access to Mathspace’s Metabase system, an internal tool used for data visualization and reporting. Attackers exploited this vulnerability to extract sensitive details including names, email addresses, school affiliations, and usage patterns. While the company stated no financial data or passwords were compromised, the scale of the breach raises concerns about privacy protections in edtech platforms. Mathspace confirmed it contained the breach, notified affected users, and engaged cybersecurity experts to investigate.
Mathspace said unusual activity in its Metabase environment triggered internal security alerts, prompting an immediate investigation. Forensic analysis confirmed unauthorized data access over a limited timeframe before the system was secured. The company emphasized that its core learning platforms remained operational and unaffected during the incident. Affected individuals received guidance on monitoring for phishing attempts and securing personal accounts.
In response, Mathspace has implemented enhanced monitoring protocols, restricted access to internal reporting tools, and accelerated plans for multi-factor authentication across all administrative systems. The platform is also undergoing a third-party security audit to identify additional weaknesses. Leadership stated they are prioritizing transparency and will provide updates as the investigation progresses, while cooperating with data protection authorities in relevant jurisdictions.
What data was stolen in the Mathspace breach? Attackers accessed names, email addresses, school or organization names, and information about how users interacted with the Mathspace platform. No passwords, payment details, or government-issued identifiers were exposed.
Is the Mathspace learning platform still safe to use? Yes, Mathspace confirmed its core educational services were not compromised and continue to operate normally. The breach was limited to an internal reporting system, not the student-facing learning environment.
Will affected users receive compensation or identity protection? Mathspace has not announced specific compensation or identity protection services at this time. Users are advised to remain vigilant against suspicious communications and follow standard online safety practices.