Mathspace Breach Put School Records Through Metabase
Mathspace said attackers breached its self-hosted Metabase reporting system and stole data on more than 1 million students, staff, parents, and guardians across Australia and New Zealand. The company said the unauthorized access began on August 10, the data download happened on August 27, and it confirmed the incident on September 3.
The flaw let attackers reach administrator access in the internal reporting tool without a legitimate login, then pull information from the reporting database behind it. In plain terms, a dashboard that was meant to summarize data became a path into the underlying school records, which is why the incident affected a centralized store rather than a customer-facing account page.
For schools and SaaS teams that run self-hosted BI tools against live personal data, the exposure sits in the reporting layer itself: once that layer falls, the breach can spread across linked identities and relationships that ordinary account-by-account incident response may miss. Mathspace said no passwords or authentication tokens were exposed, but the incident still shows how much a single analytics system can concentrate.