A compromised analytics platform exposes 1.08 million ed-tech users
Mathspace disclosed that attackers exploited an unpatched vulnerability in its self-hosted Metabase reporting environment. The flaw was patched by Metabase on August 6; unauthorized access began August 10, while Mathspace updated its instance August 29. Names, emails and account metadata for 1,079,819 Australian and New Zealand users were exposed, including inactive accounts. Academic records and authentication credentials were reportedly unaffected.
Why it matters for leaders
The lesson is broader than this vendor: internal analytics tools connected to production data require the same patch SLAs, logging and compromise checks as public-facing systems.
Cost, service, risk & adoption
Cost—notification, forensics and phishing response. Service—instruction remained available. Risk—retained inactive data enlarged the blast radius. Adoption—family trust can be damaged even when academic records are untouched.
Read the original sources
Summary and leadership analysis from the September 5–11, 2026 brief. The edition’s selection notes explain source access and evidence limitations.
