# Alvin Savoy

Type: Person

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/alvin-savoy
Canonical HTML page: https://getcyberbrief.com/entity/alvin-savoy

## Timeline

- **2026-09-05**: Public disclosure — CTO Alvin Savoy publishes a blog post disclosing the incident.
- **2026-09-03**: Breach confirmed — Mathspace confirms that unauthorized parties accessed the internal reporting system and downloaded data.
- **2026-08-29**: Mathspace upgrades Metabase — The platform applies the update but does not complete Metabase's recommended compromise checks or identify the intrusion.
- **2026-08-27**: Data exfiltrated — Threat actors download personal data from Mathspace's Australian reporting database.
- **2026-08-10**: Unauthorized access begins — Attackers gain administrator access to Mathspace's self-hosted Metabase instance without a legitimate login.
- **2026-08-06**: Metabase patches CVE-2026-72898 — Metabase releases fixes for a CVSS 10/10 SQL injection after exploitation in the wild as a zero-day. ShinyHunters later claims responsibility for hacking Metabase.

## Recent coverage (1 stories)

### Mathspace Breach: 10/10 CVE Exploited, 1M+ Records Stolen
2026-09-08 11:11:59 · Sentiment: Strongly negative · Impact: 6/10 · Sources: 2

Attackers exploited CVE-2026-72898, a CVSS 10/10 SQL injection in self-hosted Metabase, to obtain admin access without a legitimate login. Mathspace's delayed patch—23 days after fixes shipped—allowed exfiltration of personal data belonging to 1,079,819 people. The incident underscores patch-latency risk and the need to complete vendor compromise checks after updating.
Full story: https://getcyberbrief.com/story/mathspace-metabase-cve-2026-72898-breach-1m

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.