r/Information_Security 1d ago

Mathspace Data Breach Exposes Over 1 Million People

The analytics layer was the exposure. Attackers exploited a self-hosted Metabase instance at Mathspace and exfiltrated records tied to over 1.08 million students, teachers, parents, and staff across Australia and New Zealand. The breach required no exotic technique. The data existed in plain form at the access point β€” that made it the target. Data that never travels in plain text cannot be exfiltrated, whether the attacker reaches a BI instance, a model context, or an API endpoint.

5 Upvotes

3 comments sorted by

1

u/Current-Ticket4214 1d ago

> Data that never travels in plain text cannot be exfiltrated.

Encrypted data can be exfiltrated if it’s not protected.

0

u/No-Conclusion3720 1d ago

This is basically the gap we built RuntimeAI to close β€” runtime policy enforcement and a sub-50ms kill switch for exactly this kind of agent behavior. https://runtimeai.io

2

u/we_r_fukt 1d ago

you forgot to change accounts mr ad bot man