Executive Summary
On August 10, 2026, threat actors exploited a critical SQL injection vulnerability in Mathspace's self-hosted Metabase instance, gaining administrator access and stealing personal data from over 1 million students, staff, and parents across Australia and New Zealand. The attack was executed by the ShinyHunters extortion gang, who downloaded the data on August 27 before the breach was confirmed on September 3. This incident was part of a broader campaign targeting multiple organizations' Metabase installations worldwide, affecting companies including Trezor, Framework, and Tally.
This breach highlights the critical importance of securing internal reporting systems and data analytics platforms, as threat actors increasingly target business intelligence tools that often have broad database access. The incident demonstrates how zero-day vulnerabilities in widely-used SaaS tools can be weaponized at scale, creating cascading impacts across multiple organizations simultaneously.
Why This Matters Now
Educational technology platforms are increasingly targeted as they contain vast amounts of sensitive student and family data, while organizations struggle to secure complex third-party integrations and self-hosted business intelligence tools that often lack robust security controls.
Attack Path Analysis
Attackers exploited a critical SQL injection zero-day vulnerability in Mathspace's self-hosted Metabase instance to gain administrator access without legitimate credentials. Once inside the internal reporting system, they maintained persistent access for over two weeks before exfiltrating personal data of 1,079,819 students, staff, and parents from Australian and New Zealand databases, causing significant privacy impact and regulatory exposure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited a critical SQL injection zero-day vulnerability in Mathspace's self-hosted Metabase installation to gain unauthorized administrator access to the internal reporting system without legitimate login credentials
Related CVEs
CVE-2023-38646
CVSS 9.8SQL injection vulnerability in Metabase H2 database allows remote code execution through crafted setup requests.
Affected Products:
Metabase Metabase – < 0.46.6.1, < 0.45.4.3, < 0.44.7.3, < 0.43.7.4, < 0.42.6.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Sudo and Sudo Caching
Valid Accounts
Data from Local System
Exfiltration Over C2 Channel
Stored Data Manipulation
File and Directory Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
GDPR – Security of Processing
Control ID: Article 32
PCI DSS 4.0 – Software Engineering Techniques for Secure Development
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
CISA ZTMM 2.0 – Application Security
Control ID: Applications and Workloads
NIS2 Directive – Cybersecurity Incident Reporting
Control ID: Article 21
DORA – Identification
Control ID: Article 8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Primary/Secondary Education
Direct exposure through Mathspace platform breach affecting 1M+ students/staff. Metabase vulnerabilities enable data exfiltration requiring enhanced egress security controls.
Higher Education/Acadamia
Educational institutions face similar Metabase reporting system vulnerabilities. Zero trust segmentation and anomaly detection critical for protecting student data.
Information Technology/IT
IT sectors using Metabase instances vulnerable to SQL injection attacks. Cloud firewall and intrusion prevention systems essential for blocking exploit traffic.
Computer Software/Engineering
Software companies with self-hosted analytics platforms at risk. Multi-cloud visibility and encrypted traffic capabilities needed to prevent lateral movement attacks.
Sources
- Mathspace discloses data breach affecting over 1 million peoplehttps://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/Verified
- Mathspace Data Breach - What Happened and What Affected Users Should Knowhttps://blog.mathspace.co/mathspace-data-breach-what-happened-and-what-affected-users-should-know/Verified
- CVE-2023-38646 - NVD Detailhttps://nvd.nist.gov/vuln/detail/CVE-2023-38646Verified
- Metabase Security Advisory 0.46.6.1https://www.metabase.com/blog/security-advisory-0.46.6.1Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained the attacker's ability to exploit the SQL injection vulnerability and traverse Mathspace's internal systems. The segmented architecture would likely have reduced the blast radius from over 1 million exposed records by isolating the compromised Metabase instance from critical database resources.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The compromised Metabase instance would likely have been contained within its designated security perimeter, potentially limiting the attacker's ability to reach sensitive database systems and reducing their administrative scope across the broader infrastructure environment.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely have restricted the elevated privileges to the immediate Metabase workload context, potentially preventing the administrator access from extending to connected database systems and reducing the scope of accessible resources.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have blocked or significantly constrained unauthorized database connections from the compromised Metabase instance, potentially preventing direct access to the Australian reporting database and reducing the attacker's reconnaissance capabilities.
Control: Multicloud Visibility & Control
Mitigation: Enhanced visibility controls would likely have detected the anomalous 17-day persistence pattern and unusual database access behaviors, potentially triggering automated response mechanisms that could have constrained the attacker's operational timeline and reconnaissance activities.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely have blocked or significantly constrained the large-scale data download attempt, potentially preventing the bulk extraction of over 1 million records and limiting the attacker's ability to transfer sensitive personal information outside the secure environment.
While some personal data exposure might still have occurred through the initial compromise, the overall impact would likely have been significantly reduced from 1,079,819 affected individuals to a much smaller subset, limiting regulatory exposure and privacy violations across the educational platform.
Impact at a Glance
Affected Business Functions
- Online Learning Platform
- Student Information Management
- Educational Content Delivery
- Parent-Teacher Communication Portal
Estimated downtime: N/A
Estimated loss: N/A
Personal information of 1,079,819 individuals including students, parents, guardians, and school staff from Australia and New Zealand. Data included names, email addresses, and potentially school affiliations but excluded academic records, passwords, authentication tokens, or assessment data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to isolate internal reporting systems from broader network access and limit blast radius of application vulnerabilities
- • Deploy egress security controls with policy enforcement to detect and prevent unauthorized data downloads from internal databases to external destinations
- • Enable multicloud visibility and control to monitor anomalous database access patterns and suspicious data export activities across internal systems
- • Establish encrypted traffic inspection capabilities to detect SQL injection attempts and malicious payloads targeting application vulnerabilities
- • Implement threat detection and anomaly response systems to identify persistent unauthorized access and extended dwell times in critical data systems



