OptMsg Breach Breakdown: Mathspace

Mathspace Data Breach: 1.08 Million Students and Parents, What to Watch For

Priya’s son has used Mathspace for homework since Year 7. She set up the parent account with her own email address and forgot about it. This week that address, her name, and a record showing she is a parent at a school with its own email domain sit in a file downloaded by someone who has not been identified. The next email that looks like it comes from the school, asking her to sign in to see a message about her son, will be hard to tell from the real thing.

Confirmation: confirmed by the company. Mathspace published a breach notice on 5 September 2026 and updated it on 6 September.

What happened

On 3 September 2026, Mathspace confirmed that attackers had accessed an internal reporting system and downloaded records on 1,079,819 students, parents or guardians, teachers and staff. The company’s CTO, Alvin Savoy, set out the timeline in a notice on the Mathspace blog.

The way in was Metabase, a reporting tool Mathspace ran on its own servers. Metabase published a critical advisory and a patch on 6 August 2026. Mathspace says its vulnerability-notification process did not flag the advisory, and the instance was not updated until 29 August. The attackers had been inside since 10 August and downloaded the Australian reporting database on 27 August. Mathspace found the earlier access on 3 September while reviewing logs.

Mathspace notified school contacts on 4 September, reported the incident to the Australian Information Commissioner, the Australian Cyber Security Centre and New Zealand’s Privacy Commissioner and National Cyber Security Centre the same day, and began emailing affected individuals on 6 September. It says it has no evidence so far that the data has been published or sold, and the attacker’s identity is unknown.

BleepingComputer reported that the same Metabase flaw has been used against other companies over the past month, including Framework, Tally and Trezor’s shipping provider, and that the extortion group ShinyHunters has been linked to that campaign. Mathspace has not attributed its own breach to anyone.

Mathspace is used by thousands of schools in Australia, New Zealand, the US and the UK, but the company says the stolen records cover Australia and New Zealand only.

What was exposed

Mathspace says the exported data included user ID, username, first name, last name, email address, country, time zone, user type, email-verification status, and the dates each account joined, last logged in and was last active. Not every field was present for every person. Passwords, password hashes, single sign-on tokens, academic records and results were not taken.

What each item is worth to a criminal:

  • Name plus email address plus “parent” or “student” as the user type. That is a ready-made mailing list for a message dressed as the school, the app, or the education department, with the right name at the top.
  • Email addresses on a school domain. Mathspace says the file did not link accounts to schools, but a school-issued email address gives the school away. A phish to a teacher can then name the school correctly.
  • Student usernames and internal IDs. On their own, little. Quoted in a fake “your child’s account” email, they make it look like it came from inside the system.
  • Join and last-login dates. Small details that make a scam message read as real: “we noticed you have not logged in since March.”

Nothing in this breach is a password. That matters below.

What to do now

The practical risk is the follow-up: an email or text that uses your name, your child’s school, or the breach itself as the hook to get you to click or hand over a code. Most of what protects you has nothing to do with OptMsg.

1. Treat any message about Mathspace, your school, or this breach with suspicion, including the ones that look right. Mathspace’s own notice makes this point: the incident is real, but that does not make every message about it genuine. Do not follow links in them. Open the app or the school’s website yourself. 2. Verify through a channel you already have. Mathspace says to start a new email to data-breach-response@mathspace.co rather than reply to anything you received. For the school, use the number or portal you already use. 3. Do not type a password or a verification code into anything that arrived by email or text. A real school or app does not need you to confirm a code sent to your phone. 4. If you reused your Mathspace password anywhere else, change it there. No password leaked here, and Mathspace is not forcing a reset, but a criminal holding your email address will try it against sites where a password did leak. A password manager makes unique passwords painless. 5. Turn on the strongest sign-in each account offers, starting with your email account, because it is the reset route into everything else. A passkey where available, an authenticator app otherwise. 6. Talk to your child. Students got these emails too. Mathspace’s advice to students is to ask a parent, guardian or teacher before acting on any unexpected message. Say it before the message arrives. 7. Watch for unexpected password-reset emails on any account tied to the exposed address. That is the sign someone is trying the door.

How OptMsg changes this exposure

Honestly, and at its real size: OptMsg would not have prevented this breach. It happened at Mathspace, in Mathspace’s systems. What an opt-in inbox changes is what happens to you afterwards.

Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. OptMsg’s patent-pending opt-in technology means the fake “message from your child’s school” email lands in Trash, where you are not reading it under time pressure; the school and the app reach your Inbox only if you approved them as senders. Only people you approve can reach your inbox. Everyone else goes to Trash.

Then the password point. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. When a criminal takes an email address from this file and pairs it with a password from some other breach, the pair opens nothing at OptMsg — there is no password on the account to match.

What that does not cover: a text message to your phone, a phishing page you open yourself, a school account that uses its own password, or someone with your unlocked phone. Those are the steps above.

If you want the next breach’s follow-up mail to land in Trash instead of in front of you, see how Simple by Design works, or read what opt-in email is and how it shields your inbox.

Ready for an inbox that stays quiet after a breach? Create Your Account.

Your Inbox. Your Rules.

Frequently asked questions

Was my child’s schoolwork or grades exposed in the Mathspace breach? Mathspace says no. Academic records, learning activities, results and assessment records were not in the stolen data. The exposed fields were names, email addresses, usernames, internal user IDs, country, time zone, user type and account dates.

Do I need to change my Mathspace password? Mathspace says passwords and password hashes were not exposed and it is not requiring a reset. If you used the same password on another service, change it there and make it unique.

How do I know if I am affected? Mathspace says it began emailing affected individuals on 6 September 2026 and notified schools on 4 September. Only people in Australia and New Zealand were affected. To check, start a new email to data-breach-response@mathspace.co rather than replying to a message you received.

I stopped using Mathspace years ago. Am I still affected? Possibly. Mathspace says an account did not need to be active for its record to be in the reporting database, and leaving a school does not by itself mean your information was unaffected.

Would OptMsg have stopped this? No. The breach happened at Mathspace. What OptMsg changes is the aftermath: unapproved senders go to Trash rather than your Inbox, and there is no password on an OptMsg account for a leaked credential to match.

Sources

Scroll to Top