A data breach affecting more than one million students, parents, and teachers across Australia and New Zealand has produced one of the clearest test cases the Australian cyber insurance market has seen for how patch-management obligations in policy wordings translate into real claims consequences. Online mathematics platform Mathspace confirmed on September 6, 2026, that it had notified the Office of the Australian Information Commissioner (OAIC), the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), New Zealand’s Office of the Privacy Commissioner (OPC), and New Zealand’s National Cyber Security Centre (NZ NCSC) on September 4, after confirming the breach the previous day.
The breach originated in Mathspace’s self-hosted installation of Metabase, a business intelligence platform used for internal reporting. On August 6, 2026, Metabase published a critical security advisory for CVE-2026-72898, an unauthenticated SQL injection vulnerability carrying a CVSS v3.1 score of 10.0 – the maximum. The vulnerability could allow a remote attacker to gain administrator access to an affected Metabase instance. CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalogue.
Mathspace’s own disclosure states that its existing vulnerability-notification process “did not identify and escalate that advisory for action.” The company updated its Metabase instance on August 29 after a later Metabase notice came to its attention. Unauthorised access had begun on August 10 – four days after the advisory was published. Data was confirmed as downloaded on August 27. At the time of updating, Mathspace did not complete the additional compromise checks recommended for potentially affected systems. A total of 1,079,819 individuals were affected. Exposed data includes names, email addresses, user IDs, usernames, time zones, and login metadata. No passwords, academic records, or financial information were compromised. Mathspace said it has “no evidence so far that the data has been published, distributed, sold or otherwise misused.”
The technical facts place this incident squarely within underwriting conditions that at least one major insurer has already made explicit. Coalition chief underwriting officer Tiago Henriques has noted that at least one well-known insurer excludes losses arising from CVEs with a CVSS score above 8.0 where a patch has been available for three weeks and not applied. CVE-2026-72898 carried a score of 10.0. The patch was available from August 6. Mathspace applied it 23 days later on August 29 – by which point data had already been exfiltrated. In the Australian market, major underwriters now use third-party telemetry and external scanning to validate patching levels and exposure before quoting. A discrepancy between attested and actual patch cadence will surface during underwriting, not only at claims time.
The ASD’s Essential Eight recommends patching internet-facing services within 48 hours of a critical vulnerability being identified. In the 2025 Commonwealth Cyber Security Posture report, 22% of Australian government entities achieved Essential Eight Maturity Level 2 or higher across all eight mitigation strategies. Separately, 59% said their use of legacy technologies had affected their ability to implement the Essential Eight.
The Mathspace breach fits a pattern that Australian insurers have been tracking closely. Vicky Sheridan, senior claims specialist for cyber at AXA XL in Australia, has pointed directly to this category of exposure. “We’re also seeing growing exposure to cyber risks arising from third-party technology providers,” Sheridan said, citing a compromise of the Canvas learning management system that disrupted more than 9,000 educational institutions globally. She added: “Such incidents underscore the extent to which localised disruptions can trigger cascading effects across interdependent organisations, with the potential to generate material operational, financial, and reputational impacts.”
Kieran Doyle, partner and head of cyber, data, and technology at Wotton Kearney, noted a recent increase in claims activity that encompasses exactly the category of incident Mathspace represents. “The past few months have brought an increase in activity beginning with an influx of ransomware, with incident numbers running above the yearly average,” Doyle said. On non-ransomware incidents – including privacy breaches – he added: “The risk was always there but perhaps went undetected until now.” Both comments were made in the context of Insurance Business Australia’s 2026 5-Star Cyber Report.
The Mathspace incident is not isolated. The education sector recorded 81 Notifiable Data Breach (NDB) notifications in 2025, placing it joint fifth among sectors by volume, according to the OAIC. The breach follows a broader pattern of cyber incidents involving education technology providers. PowerSchool’s December 2024 breach reportedly affected about 62 million students and millions of educators. In the US, the Federal Trade Commission (FTC) also took action against education technology provider Illuminate Education in December 2025 over alleged failures to adequately protect students’ personal data, with the order finalised in June 2026.
Separately, PowerSchool agreed to a US$17.25 million proposed settlement in a privacy class action concerning allegations about data collected through its Naviance platform. Underwriters reviewing education-sector risks should be asking clients about their reliance on third-party learning-management platforms, vendor-access controls, and whether they have tested incident-response plans for supply-chain breach scenarios.
At the federal level, Australia’s Privacy Act 1988 and the Notifiable Data Breaches (NDB) scheme apply where a breach is likely to result in serious harm. The OAIC received 1,205 data breach notifications in 2025 – an 8% increase from 2024 and the highest annual total since the mandatory NDB scheme commenced in 2018. Australian Privacy Commissioner Carly Kind said: “The threat posed to Australian businesses and organisations by data breaches is substantial and rising year on year.”
In Queensland, the Information Privacy and Other Legislation Amendment Act 2023 introduced a Mandatory Notification of Data Breach scheme for public-sector agencies from July 1, 2025. Where an agency reasonably suspects a breach may be an eligible data breach, it must assess the incident within 30 days, unless an extension applies. If it determines that an eligible data breach has occurred, it must notify the Information Commissioner and affected individuals as soon as practicable, subject to exemptions. Queensland’s Department of Education, as a public-sector agency, is subject to the scheme.
In New Zealand, organisations must notify the OPC of a privacy breach that has caused or is likely to cause serious harm. The OPC says organisations should notify it as soon as practicable and expects notification within 72 hours of becoming aware that a breach is notifiable. Failure to notify the Commissioner of a notifiable privacy breach is an offence and may result in a fine of up to NZ$10,000.
The Australian Institute of Criminology’s Cybercrime in Australia 2025 report, which drew on a survey of 10,593 online Australians, recorded a second consecutive annual fall in the share holding cyber insurance, down from 4.6% in 2024 to 3.7% in 2025 – even as Australian Prudential Regulation Authority (APRA) quarterly data shows the cyber class posted a positive insurance service result in each of the three most recent quarters: $17 million in September 2025, $10 million in December 2025, and $10 million in March 2026.
The Mathspace breach gives brokers with education sector or SaaS-dependent clients a specific and timely conversation framework: Do third-party vendors in your client’s supply chain have patch management processes that would have caught a CVSS 10.0 advisory within 48 hours? Does your client’s cyber policy address cross-border aggregation risk across Australia and New Zealand? And does coverage account for notification costs under three separate regulatory regimes simultaneously?
“We’re truly sorry this happened and are taking steps to prevent similar breaches in the future. Protecting the information entrusted to us by students, families, and schools is our responsibility,” Mathspace said in its breach disclosure. Individuals who believe their data may have been affected can contact Mathspace at [email protected].