Records on 1,079,819 students, parents and school staff in Australia and New Zealand were downloaded from Mathspace's internal reporting system on 27 August by attackers who had been inside it since 10 August, the Sydney maths-education company has confirmed. The intruders used a vulnerability in Metabase, an open-source reporting tool Mathspace runs on its own servers, that Metabase had disclosed and patched on 6 August. Mathspace did not apply the patch until 29 August, and did not run the compromise checks Metabase recommended when it did. Notifications to individuals began on Sunday.

For each affected person the stolen fields can include a user ID, username, first and last name, email address, country, time zone, user type, whether the email was verified, and the dates the account was created, last logged in and last active. Mathspace says no academic records, results, password hashes, login tokens or single sign-on credentials were taken, and that the records do not link accounts to schools. It adds a qualification: "for schools with identifiable email domains, we understand this may be possible." A school email address usually names the school.

The company's account of its own failure is direct. "Our existing vulnerability-notification process did not identify and escalate that advisory for action," the notice, written by Mathspace's Alvin Savoy, says. "We updated our instance on 29 August after a later Metabase notice came to our attention." And: "At the time of updating, we did not complete the additional compromise checks recommended for potentially affected systems." The breach was confirmed only on 3 September, when a review of historical logs showed the access had begun before the update.

The flaw, CVE-2026-72898, is an SQL injection in Metabase's password-reset endpoint that lets anyone on the internet gain administrator access without logging in. Metabase's advisory rated it 10.0 out of 10, the maximum, and said the company had "confirmed active exploitation". Metabase's own cloud service was hit first. "We recently identified that Metabase Cloud was attacked by someone utilizing an unknown ("0-day") security vulnerability in versions 1.58 and above," Metabase's Sameer Al-Sakran wrote on 6 August, warning that customers running their own copies might also be exposed. The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalogue on 11 August with a 14 August deadline for federal agencies. Mathspace's patch came 15 days after that deadline.

The sequence, all from Mathspace's own notice and the vendor's records, runs: advisory and patch on 6 August; first unauthorised access to Mathspace on 10 August; the US catalogue listing on 11 August; a second round of hardened Metabase releases from 12 August; the download of the Australian database on 27 August; Mathspace's update on 29 August; confirmation of the breach on 3 September; regulators and schools told on 4 September; the public notice on 5 September, expanded on 6 September.

That expansion matters. The version published on Sunday added fields that earlier communications had left out. "This is more information than names and email addresses alone," the notice says. "Our earlier communications did not describe the account details fully." It also brought forward direct notifications: "Schools informed us that they wanted individuals to be informed as soon as possible, and we have started sending notifications as of 6th of September." Mathspace has notified the Office of the Australian Information Commissioner, the Australian Signals Directorate's cyber security centre, their New Zealand counterparts and state and territory education departments. None had issued a public statement by Tuesday, and the OAIC's stated policy is not to comment on individual notifications. Mathspace says it has no evidence the data has been published, sold or misused, and it is not asking anyone to reset a password, because none were taken.

The OAIC received 1,205 data breach notifications in 2025, the most in any year since the scheme began in 2018, and education was the fifth most-notified sector with 81. A single notification covering more than a million people, most of them school-aged, will sit near the top of the 2026 count on its own.

What is known is how the attackers got in, when, and what they took. What is not known is who they are or what they intend to do with a million names and email addresses. Metabase remains offline at Mathspace, its API keys revoked and database credentials rotated, and the company says a post-incident review will change how it handles vendor advisories. The advisory it missed ended: "Please upgrade your Metabase instance ASAP."