Your Child's School App Was Breached โ€” What Parents Should Do Now

The Mathspace breach exposed over a million Australian and NZ students and parents. What was taken, what it enables, and three things to do this week.

Published 2026-09-08 ยท Updated 2026-09-09

The short version

  • Mathspace disclosed a breach affecting 1,079,819 people across Australia and New Zealand, most of them school students.
  • Names, usernames and email addresses were exposed, but no passwords, login tokens or academic records, so this is about phishing, not password panic.
  • The biggest risk is emails that name your child, their account and the platform they use for homework, which makes them look genuine.
  • Parents can ask the school specific questions, and new Australian rules on children's online privacy are due by 10 December 2026.

What happened in the Mathspace breach?

Your child's school signed them up for an app. They used it for homework. Now that app has been breached.

In early September 2026, the maths learning platform Mathspace disclosed a breach affecting 1,079,819 people across Australia and New Zealand. Most of them are school students; parents and school staff are in there too.

Attackers got in through an unpatched, self-hosted copy of an internal reporting tool, the kind of back-office dashboard that sits behind a product rather than in it. They reached an internal reporting system. Unauthorised access dated back to 10 August, the data was exported on 27 August, and it was only detected on 3 September. That's roughly 24 days between the break-in and anyone noticing.

Mathspace says the Office of the Australian Information Commissioner (OAIC) and the Australian Signals Directorate's cyber centre have both been notified.

What data was exposed, and what wasn't?

According to the company's disclosure and news reports, the exposed fields were user IDs, usernames, first and last names, email addresses, country, time zone, user type (student, parent or staff), email-verification status, and login and join dates.

What wasn't taken matters just as much. No passwords. No login tokens. No single sign-on credentials. No academic records.

That changes the honest advice. The usual reflex after a breach is "reset every password you own". Here, that would be busywork. The real risk isn't someone logging in as your child. It's someone writing to your child, or to you, and sounding completely legitimate.

Why a name and an email are enough for a convincing scam

Think about what a scammer can do with a first and last name, an email address, a username, and the knowledge that this person is a student on a maths platform their school uses.

They can write an email that uses your child's real name and real username, mentions the platform, and says something plausible: "Your teacher has shared new homework, log in here." Or "Your account will be closed unless a parent confirms your details." Because the platform is used through schools, the scammer can reasonably guess there's a school behind the account and write as if they're from it.

For a parent, the version might be a "school fee" or "excursion payment" request that looks right because it names your child. For school staff, it might be an urgent message about student records.

This isn't hypothetical hand-wringing. A Sophos survey of education IT leaders, released the same week, found that compromised identities were involved in 85 per cent of education-sector ransomware, and malicious email was the leading root cause. Schools and the platforms they use are a target, and email is the front door.

Three things parents can do this week

None of these needs technical skills. They need a conversation and a few minutes.

  1. Talk to your child about proof. An email that knows their name, their school or their homework app is not proof it's real. Scammers can know all of that now. Teach them to go to the app or the school website directly rather than clicking a link in an email.
  2. Set a family rule for "urgent" messages. Anything asking for a password, a payment, a code or a photo gets shown to a parent first. No exceptions, no embarrassment.
  3. Treat payment and account requests that mention your child as unverified. Check them through the school's usual channel, such as the school office phone number or the parent portal you already use, never through the email itself.

Mathspace says no passwords were taken, so you don't need to reset your child's account because of this breach. If they reuse the same password elsewhere, though, now is a good moment to fix that anyway.

What should I ask my child's school?

Schools choose these platforms, often with good intentions and limited budgets. It's reasonable, and useful, to ask how those choices are made. A polite, specific email works better than a heated one. Some questions worth asking:

Which apps and platforms have student accounts been created on, and what information does the school provide to set them up?

Does the school check a provider's security and privacy practices before signing up, and is there a list parents can see?

Can students use an account that doesn't include their full name, or an email address that isn't their main one?

How will the school tell parents if another platform it uses is breached, and how quickly?

Don't expect perfect answers. Many schools are working this out in real time. But questions from parents are how schools learn that families care, and that shapes the next procurement decision.

Give every app its own address

One practical habit protects both you and your child from the next breach. Instead of giving every app the same email address, give each one its own alias: a separate forwarding address that delivers into your normal inbox but can be switched off at any time.

If phishing starts arriving at the alias you gave one homework app, you know exactly which service leaked, and you can shut that address down without touching anything else. It also means a scammer holding one leaked address can't easily link it to your child's other accounts.

Free services such as SimpleLogin and addy.io make aliases easy, and parents can set them up for a child's non-school sign-ups. Where the school creates the account, you may not get a choice, which is one more reason to ask the questions above. If you'd like a family inbox built around aliases and encryption from the start, we keep a separate site, NoSpyEmail, that looks at the private email options that hold up to that kind of scrutiny.

Are the rules for children's apps changing in Australia?

Yes, on two fronts, though neither is settled yet.

The OAIC's Children's Online Privacy Code must be registered by 10 December 2026. It's designed to strengthen protections for anyone under 18 in digital environments, and a breach of the Code will be a breach of the Privacy Act. Legal commentators have pointed out that the draft was written against the current privacy principles, so if the wider Tranche 2 reforms pass, the Code may need rewriting.

Separately, the Government released an exposure draft of a Digital Duty of Care on 8 September. It reaches beyond social media: online games, apps and AI chatbots would have to protect under-18s from addictive design and harmful content. That means the rules could cover your child's AI chatbot and games, not just their social feeds. The Coalition has said it opposes the bill in its current form, so the final shape is uncertain.

Also on the table is a proposed 72-hour deadline for notifying breaches, replacing the current "as soon as practicable" standard. Against a 24-day detection gap, that would be a very different world.

How do I make a complaint?

Start with the provider and the school. Ask what data about your child was held and what's changed since. Answers may be slow, and that's worth knowing in itself.

If you're not satisfied, Australian families can complain to the OAIC, and New Zealand families to the Office of the Privacy Commissioner. Complaints are free. Individually they can feel small, but regulators act on patterns, and a pattern is exactly what a million affected families represents.

If you'd like to see whether your own email addresses have turned up in other breaches, Have I Been Pwned is a free place to check.

Frequently asked questions

Were passwords taken in the Mathspace data breach?

Mathspace says no passwords, tokens, single sign-on credentials or academic records were taken. Exposed data included names, usernames, email addresses, user type and login dates.

Do I need to reset my child's Mathspace password?

Not because of this breach, since passwords weren't exposed. The more important step is teaching your child to be wary of emails that use their name or mention their school app.

How many people were affected by the Mathspace breach?

Mathspace disclosed that 1,079,819 people across Australia and New Zealand were affected, most of them school students, along with parents and school staff.

What is the Children's Online Privacy Code?

It's an OAIC code designed to strengthen privacy protections for under-18s online. It must be registered by 10 December 2026, and breaching it will be a breach of the Privacy Act.

Ready to act on this?

We've reviewed the tools so you don't have to.

Give every app its own address โ€” see private email options โ†’