Plan
active
Mathspace breach via Metabase exposes 1M+ student and staff records
- Engineer — Plan: Metabase is widely self-hosted as an internal analytics/BI tool; audit your own Metabase instance for misconfigurations or unpatched CVEs that may match the attack vector used here, and verify network exposure of the service.
- SOC/IR — Skip
- Leader — Learn: A 1M+ record breach via an internal BI tool (Metabase) at an ed-tech vendor illustrates third-party analytics platform risk, but requires no immediate leadership action for organizations not using Mathspace.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.