Public services and institutions

ANSSI and DINUM: investigation into Metabase-related incidents

Reports in early October describe incidents involving public-sector services and Metabase, alongside a judicial investigation. Facts and uncertainties.

Conceptual illustration: ANSSI and DINUM: investigation into Metabase-related incidents
Conceptual illustration · SecurCheck

What is confirmed

Early October reporting described data exposure at French public-sector organisations and alleged exploitation of a Metabase vulnerability.

On October 5, specialist reporting said the Paris prosecutor had opened an investigation into the reported ANSSI incident.

What it means

The existence of an investigation does not independently establish the scope of data exfiltration or every attacker claim.

Business intelligence applications may combine data from many systems, making access controls, segmentation and audit logs particularly important.

What this incident reveals

The existence of an investigation does not independently establish the scope of data exfiltration or every attacker claim.

Practical steps to take

Inventory exposed Metabase instances and check their versions against applicable security advisories.

Revoke compromised access and review dashboard export permissions.

What to do

Inventory exposed Metabase instances and check their versions against applicable security advisories.

Revoke compromised access and review dashboard export permissions.

Review available logs before concluding that data was exfiltrated.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. 01net — enquête ouverte le 5 octobre
  2. IT-Connect — analyse Metabase