Security1 publisher2 min readPublished
Metabase published a critical fix on August 6, Mathspace's escalation process never surfaced it, and by the time the update went in on August 29 an intruder had been inside the reporting instance for 19 days and had already exported 1,079,819 records.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Four days separated the fix from the break-in. Metabase shipped patched versions alongside a critical advisory on August 6 [5]. Mathspace's investigation puts the earliest unauthorized access at August 10, Australian Eastern Standard Time [7]. The advisory was never identified or escalated internally [6], and the instance stayed vulnerable until August 29, when a subsequent Metabase notice prompted the update [8]. That is 23 days after the fix existed [2] and 19 days after someone was already inside [3]. The export from the Australian reporting database ran on August 27 [9], two days before the patch went on [4].
Mathspace also says it did not complete the additional compromise checks recommended for potentially affected systems when it applied the update [10]. That omission is why August 29 produced no detection. The Metabase flaw handed out administrator access without a legitimate login [4], so installing the fixed version closes the route and says nothing about what came through it. The intrusion was confirmed on September 3 by a review of historical logs [11], five days after the patch [6] and 24 days after the first access [5].
What the reporting instance could reach shows up in the cleanup. On September 3 Mathspace took Metabase offline, revoked its API keys, disabled Metabase database-access accounts in both its Australian and US Snowflake environments, and changed the passwords on its Metabase Cloud SQL databases [12]. A self-hosted BI front end holds standing credentials into the warehouse because that is what it is for, which is the argument for patching it on the vendor's release schedule rather than the internal ticket queue.
The public record is thin where it counts. No CVE identifier, affected Metabase version, or statement about whether the instance was reachable from the open internet appears in the account of the incident [7]. Whether this was opportunistic scanning for a freshly disclosed pre-auth bug or a targeted operation is not established; Mathspace says the attacker's identity remains unknown [13]. Its finding that there is no evidence the data has been published, sold, distributed or misused [14] describes what Mathspace can see; it says nothing about what the attacker holds.
Mathspace is not requiring password resets, because no authentication credentials were in the export [18]. On the evidence, that holds. The one user-side action that changes an outcome is retiring any Mathspace password reused on another service [18].
Ranked by verification strength, evidence, and original report placement.
The Mathspace data breach affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information.
Mathspace confirmed the incident on September 3, 2026, and said affected records involve students, parents or guardians, teachers, and Mathspace staff.
Mathspace said names, email addresses and account details were exposed, but customer passwords, single sign-on tokens and other authentication credentials were not.
The incident resulted from a vulnerability in Mathspace's self-hosted Metabase installation used for internal reporting; the flaw allowed attackers to obtain administrator access without a legitimate login.
Metabase issued a critical security advisory and patched versions on August 6.
Mathspace said its vulnerability-notification process failed to identify and escalate the August 6 Metabase advisory.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One self-report, unusually well dated
The dating is the strong part: advisory, first access, export, patch, confirmation and each notification all carry a day, and the intervals between them survive arithmetic. The weak part is that a single account from a single outlet relays a single source, Mathspace itself, on facts that only Mathspace can currently see, including the log review that established when the intruder arrived. Nothing technical is pinned down — no CVE, no version, no word on network exposure — so an outside reader cannot check the vector against Metabase's own advisory.
A fix shipped, one operator counted
Two concrete pieces of real-world behaviour are documented: Metabase made patched versions available on August 6, and one self-hosted operator took 23 days to install them. Beyond that single deployment, our coverage says nothing about how many other self-hosted instances were exposed, exploited or patched, and offers no scan data, vendor telemetry or second victim. A million affected people is one organisation's blast radius, not evidence of how far the flaw travelled.
Reads calmer than its own timeline
The framing leans on what was not taken — no passwords, no hashes, no SSO tokens, no assessments — and on the absence of evidence that anything has been published or sold. Both are true and both are early. Set against them are two admissions the same notice makes: the escalation process never surfaced a critical advisory, and the recommended compromise checks went undone at patch time, which is precisely why the intrusion surfaced by log archaeology rather than at the moment of patching. Student user IDs, verified school-domain email addresses and inferable affiliations are also better phishing material than the reassuring tone suggests.
The breached party narrates its own failure
Every fact here originates with the company that missed the advisory, published three days after it notified two privacy regulators and two national cyber agencies. That sequencing rewards precision on dates and containment steps while shaping which sentences lead: the credential exclusions and the no-misuse line come first, the process failures later. The relaying outlet covers breaches as its beat, which favours the affected-user count in the headline over the patch-management lesson underneath it. Notably, the disclosure still concedes two things that regulators will read closely, which cuts against pure reputation management.
Firm on sequence, thin on cause
I would defend the chronology and the containment inventory: they are specific, internally consistent and unlikely to be volunteered wrongly by the party they embarrass. I would not yet defend the vector beyond its functional description, the completeness of the affected-field list, or the scope statement about former users, all of which depend on investigation Mathspace says is still running while Metabase stays offline. A regulator finding or a Metabase statement would move this materially in either direction.
security
CISA ties federal patch deadlines to four yes-or-no questions about each CVE1 publisher
security
Oracle's monthly patch drop hit 925 CVEs in August, four times June's volume2 publishers
leadership
Snowflake guided FY27 growth a point below the quarter it just delivered1 publisher
product
Google's new Flash buys its benchmark wins with extra tokens1 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026