ShinyHunters claims Metabase breach days after zero-day exposes 100K+ organizations
One successful exploit could open the door to credentials and databases across thousands of connected organizations.

Image by Metabase
- ShinyHunters listed Metabase on its leak site days after the company revealed a zero-day attack.
- The flaw could give attackers admin access, database credentials, and access to data stored in connected systems.
- If ShinyHunters exploited the zero-day at scale, the potential fallout could extend across thousands of Metabase deployments.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
ShinyHunters claims Metabase just days after the data analytics platform revealed attackers had breached its systems via a now-patched zero-day – potentially exposing the credentials and connected databases for more than 100,000 organizations.
The notorious extortion group listed Metabase on its dark leak site sometime on Tuesday – its only comment on the new entry being a text-based tongue-out emoticon and a download link to one of its primary mirror servers.
Notably, the entry lacks any description of what data was allegedly stolen, how much data is involved, when the intrusion occurred, or how ShinyHunters obtained access.
Although the group traditionally lists its victims along with some basic details straight away, it is not completely unheard of for ShinyHunters to initially claim a victim on its blog, then fill in the entry several days later.
Zero-day opens door to connected databases
What makes the security incident even more worrisome is that on Thursday, August 6th, Metabase posted a notice on its website alerting customers that it had suffered a zero-day attack on its cloud servers.
“We identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above,” the business intelligence platform said.
The CVSS 10.0 critical vulnerability allows an unauthenticated remote attacker to inject SQL into the Metabase application database and gain administrator access.
Metabase says, once inside the environment, an attacker could potentially steal credentials for connected databases, gain access to the data available through those connections, and export the data to an attacker-controlled C2 server.
The company has urged self-hosted customers to immediately upgrade their Metabase installation, also noting that a system patch for direct cloud-based customers has already been applied.
100,000+ organizations use Metabase
Founded in 2015, Metabase is an open-source business intelligence and data analytics platform used by more than 100,000 organizations worldwide, according to the company's website.
Headquartered in San Francisco, Metabase's client list spans more than 150 countries.
Big-name customers include fintech giants Revolut and N26, along with Gojek, Remote, Usabilla, Coupa, Color, and Cal.com.
If ShinyHunters is behind the zero-day exploitation, potentially tens of thousands of organizations running vulnerable Metabase instances could be exposed.
As part of last week's announcement, Metabase gave customers a very specific compromise pattern to look out for – a POST /api/session/reset_password returning 400 followed by GET /api/user/current returning 200.
The company said the exploitation pattern often means an instance was the likely target.
Cybernews has reached out to Metabase for comment and is awaiting a response.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
ShinyHunters' mass hacking campaigns
Meanwhile, ShinyHunters is known for running several mass hacking campaigns in recent years using a similar MO – first compromising third-party business platforms used by corporations worldwide to infiltrate their victims.
These campaigns have included attacks targeting Salesforce environments and Okta single sign-on (SSO) accounts.
Active since 2019, ShinyHunters has been steamrolling through the names of hundreds of high-profile corporate victims since last September, with the majority attributed to its exploitation of more than 1.5 billion records tied to misconfigured Salesforce instances.
More recent victims claimed by ShinyHunters include Google, Brinks Home, Ameriprise Financial, Cushman & Wakefield, Grubhub, Eastman Kodak, 7-Eleven, Zara, and Carnival – the majority tied to Salesforce-linked data theft or extortion.
The cybercriminals have also kept busy executing their most recent June hacking spree targeting another critical zero-day vulnerability in Oracle PeopleSoft software.
ShinyHunters has also been associated with the massive 2024 campaign targeting customer instances on the popular Snowflake cloud data platform.
Check if your data has been leaked