Quick Answer
Mathspace data breach 2026: 1M+ users affected — students, teachers, parents. Exposed: names, emails, DOB, school, grade, learning progress. Edtech sector breach — FERPA implications. Mathspace is an adaptive math platform used in 3,000+ schools (BleepingComputer, 2026).
Data last verified September 2026 from BleepingComputer and Mathspace disclosures.
Mathspace data breach — what we know
| Field | Detail |
|---|---|
| Company | Mathspace (Mathspace Pty Ltd) |
| Users affected | 1,000,000+ (students, teachers, parents) |
| Discovery date | Early 2026 (exact date not disclosed) |
| Public disclosure | March 2026 (per BleepingComputer) |
| Data types | Name, email, DOB, school, grade, learning progress |
| Threat actor | Not yet publicly identified |
| Remediation | Free credit monitoring for affected individuals (minors and adults) |
| Regulatory | FERPA (US), Privacy Act (Australia), GDPR (EU) |
Source: BleepingComputer, Mathspace press release (2026).
What is Mathspace?
Mathspace is an adaptive math learning platform for K-12 schools. Mathspace provides: (1) Personalized math learning paths for students, (2) Adaptive learning technology that adjusts to each student's level, (3) Real-time feedback and step-by-step guidance, (4) Curriculum-aligned content for K-12 math standards (Common Core, Australian Curriculum, etc.), (5) Teacher dashboard for monitoring student progress, (6) Parent portal for tracking their child's learning. Mathspace is used by 3,000+ schools globally with 1M+ students (Mathspace, 2026).
What was exposed in the breach
The exposed data includes: (1) Student names, (2) Student email addresses, (3) Dates of birth, (4) School names, (5) Grade levels, (6) Math learning progress and performance data, (7) Teacher names and email addresses, (8) Parent email addresses (where provided). The breach did NOT include: (1) Financial information, (2) Passwords, (3) Social Security numbers, (4) Home addresses. However, the combination of name, email, DOB, and school could be used for targeted phishing, identity theft, and social engineering attacks (Mathspace, 2026).
Why education data breaches are particularly harmful
Education data breaches are particularly harmful because: (1) Students are minors and cannot easily detect or respond to identity theft, (2) Academic performance data is sensitive and could affect college applications or future opportunities, (3) Children's data has a longer 'shelf life' for identity thieves (the data can be used for years), (4) Schools and parents may not be aware of the breach for months or years, (5) The breach can affect students' trust in educational technology. Education breaches are governed by laws like FERPA in the US, the Privacy Act in Australia, and GDPR in the EU (US Department of Education, 2026).
Edtech cybersecurity risks
The edtech sector has been increasingly targeted by cybercriminals: (1) Edtech platforms store valuable data (student names, DOBs, performance, parents' emails), (2) Edtech often has weaker security than finance or healthcare, (3) Schools have limited IT security budgets and staff, (4) The rapid shift to online learning during and after COVID expanded the attack surface, (5) Many edtech platforms are third-party services used by schools, making them an attractive target. Recent edtech breaches include: Mathspace (1M+, 2026), PowerSchool (3.5M students, 2024), Illuminate Education (1M+ students, 2021), and Schoology (millions of users, 2020) (Cybersecurity Dive, 2026).
What Mathspace is doing in response
Mathspace has: (1) Activated incident response protocols, (2) Engaged leading cybersecurity firms, (3) Notified the relevant authorities (US Department of Education, Australian Cyber Security Centre, etc.), (4) Notified affected schools, teachers, and parents, (5) Offered free credit monitoring and identity theft protection for affected individuals, (6) Implemented additional security controls to prevent similar breaches, (7) Coordinated with law enforcement (Mathspace, 2026).
What parents and teachers should do
- Monitor for phishing emails referencing Mathspace or student data.
- Check for new accounts opened in the student's name.
- Review the credit reports of minors (where available — free in some states).
- Consider placing a credit freeze for minors in the US (free, prevents new account opening).
- Contact Mathspace for the latest updates and remediation at [email protected].
- File a complaint with the FTC at identitytheft.gov if identity theft is detected.
- Contact the school's IT department to confirm the breach and understand the school's response.
- Encourage your child to report any suspicious online activity.
What schools should do
- Communicate with parents about the breach and remediation steps.
- Review the school's data processing agreement with Mathspace.
- Consider migrating to alternative edtech platforms with stronger security.
- Implement additional security training for staff and students.
- Report the breach to the relevant education authorities (e.g., US Department of Education).
- Provide free credit monitoring to affected students where appropriate.
- Conduct a security audit of all third-party edtech platforms.
Edtech security best practices
- For edtech vendors: Implement strong authentication (MFA), encrypt data at rest and in transit, conduct regular security audits, comply with student privacy laws (FERPA, COPPA, GDPR-K), publish security policies, and notify schools promptly of breaches.
- For schools: Vet edtech vendors before adoption, review data processing agreements, limit data shared with vendors, monitor for breaches, and have a data breach response plan.
- For parents: Understand what data schools share with edtech vendors, opt out of data sharing where possible, monitor children's online activity, and report suspicious activity to the school and FTC.
Education data privacy laws
- FERPA (US): Family Educational Rights and Privacy Act — protects student education records, requires parental consent for data sharing.
- COPPA (US): Children's Online Privacy Protection Act — protects children under 13, requires parental consent for data collection.
- State student privacy laws (US): California SOPIPA, Illinois SOPPA, and others provide additional protections.
- Privacy Act 1988 (Australia): Federal law protecting personal information of Australian citizens.
- GDPR (EU): General Data Protection Regulation — protects personal data of EU citizens, applies to edtech companies serving EU students.
- UK GDPR / DPA 2018: UK equivalent of GDPR.
Resources and next steps
Visit identitytheft.gov for free identity theft recovery resources. The US Department of Education's Student Privacy Policy Office (SPPO) provides resources at studentprivacy.ed.gov. The Identity Theft Resource Center (idtheftcenter.org) provides free victim assistance. For edtech security best practices, see the Future of Privacy Forum (FPPF) and the Student Data Privacy Consortium (SDPC). For Australian privacy resources, see the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read more
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









