2026 Boston Consulting Group — unauthenticated SQL execution on BCG X Portal / x.bcg.com data warehouse (responsible disclosure)
Data compromised
High-volume third-party workforce intelligence, compensation benchmarks, consumer receipt–class rows, cloud spend telemetry, M&A research tables, and internal BCG analyst identity linkage as characterized in disclosure-era reporting
Technical writeup
Independent offensive-security research published under BCG’s responsible-disclosure program described a publicly reachable API on the BCG X analytics portal that accepted raw SQL against an internal warehouse—without authentication—exposing very large schemas of commercially licensed workforce, M&A, and consumer-transaction data plus GAMMA employee-to-engagement mappings before vendor remediation within roughly 48 hours. Follow-on industry commentary treated the episode as emblematic of AI-era external attack-surface growth at major consultancies.
Root cause
Missing authentication and excessive database privileges on an internet-exposed internal analytics API
References
- https://codewall.ai/blog/how-we-hacked-bcgs-data-warehouse-3-17-trillion-rows-zero-authentication
- https://www.f5.com/labs/articles/casi-leaderboard-shifts-developer-role-attack-and-three-concerning-incidents
- https://www.managementtoday.co.uk/consulting-sector-briefing-ethical-hacks-ai-ultimatums/management-consultancy/article/1953761