highOther

Mathspace Data Breach via Metabase Internal Reporting System

First seen Sep 8, 2026 · Updated Sep 8, 2026

data-breachedtechthird-party-riskbusiness-intelligence-toolPII-exposure

Online mathematics learning platform Mathspace disclosed a data breach affecting over 1 million students, staff, and parents after attackers compromised its Metabase internal reporting system. The breach exposed personal data likely including names, emails, and academic records tied to a widely used education platform. No technical details on the intrusion vector into Metabase have been disclosed.

Technical Analysis

The attack targeted Metabase, a business intelligence and data reporting tool commonly used to query and visualize data from internal databases, suggesting the attackers gained access to a reporting dashboard with broad read access to underlying student and staff records. Common attack paths for Metabase compromises include exposed instances with default or weak credentials, unpatched Metabase vulnerabilities (e.g., historical CVEs affecting Metabase's H2 driver or JWT handling), or stolen employee credentials used to authenticate into the admin console. The breach underscores the risk of internal analytics tools acting as a single aggregation point for sensitive data across otherwise segmented systems. There is no direct evidence of AI agent or LLM tooling involvement in this incident, but organizations that connect agent-based systems or RAG pipelines to Metabase or similar BI tools for automated reporting should note that compromised BI credentials or exposed dashboards could similarly expose data ingested by AI agents querying the same backend, warranting review of any agent integrations with internal analytics platforms.

Affected Systems

Metabase internal reporting/business intelligence platform used by Mathspace; systems and databases connected to or queried via Metabase containing student, parent, and staff PII

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) disclosed in source reporting

Remediation Steps

  1. 1

    Audit Metabase Access Controls

    Review and restrict access to Metabase instances, enforce MFA, rotate all admin and service account credentials, and disable public exposure of the dashboard.

  2. 2

    Patch and Harden BI Tooling

    Ensure Metabase is updated to the latest patched version and review configuration for known vulnerabilities in query execution and authentication.

  3. 3

    Notify Affected Individuals

    Complete breach notification obligations to affected students, parents, and staff per applicable data protection regulations (e.g., Australian Privacy Act, GDPR if applicable).

  4. 4

    Review Data Minimization Practices

    Limit the volume and sensitivity of data accessible through internal reporting tools to reduce blast radius of future compromises.

  5. 5

    Monitor for Credential Reuse

    Monitor for use of exposed credentials/PII in phishing or credential-stuffing campaigns targeting affected users.

Industries Most Exposed

educationedtechtechnology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.