Someone opened Mathspace’s reporting console in early September and never typed a password. The Sydney homework company sells maths practice to schools. The box that got hit was Metabase, a self-hosted analytics stack sitting on student, parent, and staff tables. Attackers walked in as administrators. More than a million people came out with them. If your cybersecurity program still treats internal reporting as furniture, this is your week. The charting tool was the directory.

Illustration of a data breach affecting personal records stored in a reporting system
Education vendors keep treating analytics boxes like office furniture. Attackers treat them like student information systems.

Schools bought a lesson product. What they funded, without a line item, was a query engine with administrator rights over the same families. Mathspace said the hole lived in its self-hosted Metabase install. The path was unauthenticated admin on the reporting plane. That is a data warehouse with a friendly UI and a patch cadence borrowed from a side project.

You already know this pattern if you have ever watched a so-called read-only dashboard dump a production schema. Metabase connects to whatever you let it. Charts are a presentation layer. The prize is the join. Once an attacker is admin, they are not browsing a maths app. They are browsing every table the company thought was safe because nobody on the internet was supposed to see the URL.

Admin Access Arrived Without a Password

Unauthenticated administrator on a BI tool is a completed breach the moment the page loads. You do not get a brute-force log to argue about. You do not get a ticket that says the lesson site stayed up. The reporting host just became the student directory, the parent contact list, and the staff roster in one session. Mathspace’s count, more than a million students, parents, and school staff, is what that session is worth when an education company points analytics at live data.

Districts will spend the next month asking whether their kids were in the extract. Parents will spend it asking who else had a copy. Your incident response playbook, if it starts with the public website and the student login, will burn two days proving the LMS looks clean while the actual theft finished in a tool your asset inventory lists as reporting. That delay is how a dashboard breach becomes a notification crisis.

Treat every self-hosted analytics box as a production database that learned to speak HTTP. Same secrets. Same joins. A weaker story about who patches it. The people who live in those tables are children and the adults who signed forms. You do not get to call that an internal convenience.

Your Cybersecurity Program Stops at the Product

Same week, Grindr agreed to pay £26 million to settle U.K. claims that it shared users’ personal information, including HIV status, with third parties for advertising. Different industry. Same architecture of neglect. The dating app is what users open. The leak path is the side channel that carries the sensitive fields: ad partners, SDKs, reporting. Mathspace put families in Metabase. Grindr put health status in the commercial pipe. Your threat-protection stack scores the front door. The data leaves through a system you classified as not in scope.

Grindr app branding related to a U.K. privacy settlement over sharing of sensitive user data
Grindr’s £26 million U.K. settlement is about HIV status in the ad pipe, the same class of side-channel leak as a homework vendor’s reporting stack.

Defense in depth that ends at the customer login is a drawing, not a control. A firewall in front of the homework site does nothing for a Metabase listener on another hostname, another port, another change ticket. Threat detection that never parses BI audit logs will not see a warehouse dump of parent emails. Cyber security budgets follow the logo on the app store listing. Attackers follow the database connection string in the analytics config.

This is a bad look for any vendor that sells into schools, clinics, or anyone else sitting on regulated people. You told the customer the product was the perimeter. The reporting layer and the ad layer were the perimeter that mattered. They always were.

Pull the Query Box Off the Open Internet

Do this this week, not after the next education-vendor letter. Inventory every Metabase, Superset, Looker, Grafana, Redash, and leftover dashboard instance, including the forgotten VM a data analyst stood up in 2023. Record the version, the identity provider, the databases it can reach, and whether it answers on the public internet. If you cannot prove the version, assume it is unpatched. If it has a local admin and no SSO, assume the password is a team joke.

Immediate actions if a BI box was reachable without a real login: take it off the network, preserve query and access logs, rotate every credential and key the service account could see, and treat downstream warehouses and object stores as exposed. Hunt for new admin users, saved questions that exfiltrate, and webhooks you did not create. Notify the schools or business units whose rows lived in those joins. Your incident response clock started at unauthenticated admin, not at the press blog.

Ongoing security hardening looks boring on purpose. Put analytics behind SSO and a VPN or zero-trust connector. Disable local password auth. Subscribe to the vendor’s security feed and patch on the same clock you use for the identity provider. Log every query and every permission change into the same SIEM that watches the core app. Alert on admin creation, failed-then-success bursts, and sudden exports. That is threat detection for a data plane, which is what BI actually is.

If anything on that host still offers a password prompt to the internet, you will eat brute-force noise until you ban it at the edge. Rate-limit and drop repeat offenders the way you already do for SSH and RDP; ipban-style controls belong on those remaining sockets. Windows jump boxes that can reach the same VLAN can run IPBan Pro so a sprayed login cannot pivot from the jump host into the dashboard. Threat-protection products will not invent that coverage for you. You have to name the analytics host as a crown-jewel asset and put a person on its patch and identity review every month.

School IT and MSSPs: put BI and internal reporting in the vendor questionnaire next to the LMS. Demand version proof, SSO, and a statement of which student fields the dashboard can see. If they cannot answer, you already know the Mathspace shape.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.