The Sethi Ledger

People · Practice · Possibility

Independent research for education leaders

CIO intelligence

A compromised analytics platform exposes 1.08 million ed-tech users

Mathspace disclosed that attackers exploited an unpatched vulnerability in its self-hosted Metabase reporting environment. The flaw was patched by Metabase on August 6; unauthorized access began August 10, while Mathspace updated its instance August 29. Names, emails and account metadata for 1,079,819 Australian and New Zealand users were exposed, including inactive accounts. Academic records and authentication credentials were reportedly unaffected.

Why it matters for leaders

The lesson is broader than this vendor: internal analytics tools connected to production data require the same patch SLAs, logging and compromise checks as public-facing systems.

Cost, service, risk & adoption

Cost—notification, forensics and phishing response. Service—instruction remained available. Risk—retained inactive data enlarged the blast radius. Adoption—family trust can be damaged even when academic records are untouched.

Read the original sources

Summary and leadership analysis from the September 5–11, 2026 brief. The edition’s selection notes explain source access and evidence limitations.

Download the complete edition

Continue reading

← Back to this edition