← BCG

2026 Boston Consulting Group — unauthenticated SQL execution on BCG X Portal / x.bcg.com data warehouse (responsible disclosure)

2026 Unknown records affected Share on X

Data compromised

High-volume third-party workforce intelligence, compensation benchmarks, consumer receipt–class rows, cloud spend telemetry, M&A research tables, and internal BCG analyst identity linkage as characterized in disclosure-era reporting

Technical writeup

Independent offensive-security research published under BCG’s responsible-disclosure program described a publicly reachable API on the BCG X analytics portal that accepted raw SQL against an internal warehouse—without authentication—exposing very large schemas of commercially licensed workforce, M&A, and consumer-transaction data plus GAMMA employee-to-engagement mappings before vendor remediation within roughly 48 hours. Follow-on industry commentary treated the episode as emblematic of AI-era external attack-surface growth at major consultancies.

Root cause

Missing authentication and excessive database privileges on an internet-exposed internal analytics API

References