Every one of those 1 sits in a single category, data-breach. Of the tracked stories, 1 of 1 also mention Alvin Savoy, the most common co-covered peer. We currently track 1 Cybersecurity story that mention Metabase, all published on September 8, 2026.
Figures are computed live from our source-verified story record
— see our methodology for how impact and
sentiment are derived.
What the coverage shows about Metabase
Every one of those 1 sits in a single category, data-breach. Of the tracked stories, 1 of 1 also mention Alvin Savoy, the most common co-covered peer. We currently track 1 Cybersecurity story that mention Metabase, all published on September 8, 2026. Each carries 2 original sources on average.
Stories tracked
1
Sources per story
2
Computed from the 1 stories linked to this entity, with beat comparisons drawn from all 4 Cybersecurity stories published in the same date window. Shares are omitted below five stories and comparisons below a twenty-story baseline.
Coverage cohort
Appears alongside
Other entities that clear the same relevance threshold in stories also covering Metabase. Shared-story counts are live from our verified record — not editorial picks.
CTO Alvin Savoy publishes a blog post disclosing the incident.
Breach confirmed
Mathspace confirms that unauthorized parties accessed the internal reporting system and downloaded data.
Mathspace upgrades Metabase
The platform applies the update but does not complete Metabase's recommended compromise checks or identify the intrusion.
Data exfiltrated
Threat actors download personal data from Mathspace's Australian reporting database.
Unauthorized access begins
Attackers gain administrator access to Mathspace's self-hosted Metabase instance without a legitimate login.
Metabase patches CVE-2026-72898
Metabase releases fixes for a CVSS 10/10 SQL injection after exploitation in the wild as a zero-day. ShinyHunters later claims responsibility for hacking Metabase.
Attackers exploited CVE-2026-72898, a CVSS 10/10 SQL injection in self-hosted Metabase, to obtain admin access without a legitimate login. Mathspace's delayed patch—23 days after fixes shipped—allowed exfiltration of personal data belonging to 1,079,819 people. The incident underscores patch-latency risk and the need to complete vendor compromise checks after updating.