Metabase is facing a new extortion claim while still responding to a critical security flaw that attackers used against its cloud platform. ShinyHunters added the business intelligence company to its leak site on Tuesday, several days after Metabase confirmed that an unknown attacker had exploited a previously undisclosed vulnerability. Metabase has not attributed that intrusion to ShinyHunters, so the connection between the two developments remains unconfirmed.
The ShinyHunters post offers few clues about what allegedly happened. Instead of publishing details about the intrusion or describing the information supposedly obtained, the group posted an emoticon and a link to a download mirror. No amount of allegedly stolen data was specified, and the hackers did not explain when or how they claim to have entered Metabase’s systems.
Metabase’s own disclosure provides considerably more information about the confirmed security incident. On August 6, the company revealed that Metabase Cloud had been targeted through a zero-day affecting versions 1.58 and newer. The vulnerability carries the highest possible CVSS severity score of 10.0 and can be exploited remotely without authentication.
The flaw allows SQL injection against the Metabase application database, potentially giving an attacker administrator-level privileges. That access is particularly sensitive because organizations use Metabase to connect to other databases for analytics. Metabase warned that an intruder could potentially obtain credentials for those connected systems, access information available through them, and transfer data elsewhere.
Cloud customers have already received the security fix directly from Metabase, while organizations operating their own installations were instructed to upgrade. Metabase also provided administrators with a request sequence that may indicate attempted exploitation, giving self-hosted customers a way to investigate whether their systems were targeted.
The number of organizations potentially affected by the actual attack has not been established. Metabase says its analytics platform is used by more than 100,000 organizations in over 150 countries, but that figure represents its overall user base and should not be interpreted as the number of compromised customers. Publicly featured users of the platform include Revolut, N26, Gojek, Remote, Coupa and Cal.com.
At least some organizations using Metabase have separately reported exposure connected to the vulnerability. Reporting on the incident indicates that laptop maker Framework informed customers that names, email addresses, phone numbers and physical addresses were accessed through its Metabase environment, while order and payment information was not affected.
ShinyHunters has not yet supplied technical evidence demonstrating that it exploited the same vulnerability. The group is known for data theft and extortion involving enterprise platforms, including previous campaigns targeting corporate SaaS environments, but its history cannot establish responsibility for this incident. Microsoft has separately documented activity associated with ShinyHunters involving unauthorized access and data theft from SaaS applications.
As of the latest available information, Metabase has confirmed exploitation of the zero-day but has not named the attacker responsible. ShinyHunters has claimed Metabase on its leak site, but has not disclosed enough evidence to independently verify what data it possesses or whether its claim stems from the confirmed zero-day intrusion.