Executive Summary
In March 2026, Tenable Research disclosed nine critical cross-tenant vulnerabilities, collectively termed 'LeakyLooker,' in Google Looker Studio. These flaws allowed attackers to execute arbitrary SQL queries on victims' databases, leading to potential data exfiltration, insertion, and deletion across Google Cloud Platform (GCP) services. The vulnerabilities affected organizations utilizing connectors such as Google Sheets, BigQuery, Spanner, PostgreSQL, MySQL, and Cloud Storage. Google addressed these issues following responsible disclosure in June 2025. The 'LeakyLooker' vulnerabilities underscore the evolving threat landscape in cloud environments, highlighting the necessity for robust security measures and continuous monitoring. Organizations must remain vigilant against cross-tenant vulnerabilities to safeguard sensitive data and maintain compliance with industry standards.
Why This Matters Now
The 'LeakyLooker' vulnerabilities highlight the critical need for organizations to reassess and strengthen their cloud security postures. As cloud services become increasingly integrated into business operations, the potential for cross-tenant attacks grows, making it imperative to implement stringent access controls and continuous monitoring to protect sensitive data.
Attack Path Analysis
An attacker exploited cross-tenant vulnerabilities in Google Looker Studio to execute unauthorized SQL queries on victims' databases, leading to data exfiltration and potential data manipulation across different cloud tenants.
Kill Chain Progression
Initial Compromise
Description
The attacker identified and exploited cross-tenant vulnerabilities in Google Looker Studio, allowing unauthorized access to victims' databases.
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
SQL Stored Procedures
Valid Accounts
Data Manipulation: Stored Data Manipulation
Data from Cloud Storage Object
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Software Development
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Data Security
Control ID: Pillar 3: Data
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
LeakyLooker cross-tenant SQL injection vulnerabilities could expose sensitive financial data through compromised Google Cloud analytics platforms, violating compliance frameworks.
Health Care / Life Sciences
Cross-tenant database access flaws threaten patient data confidentiality in Google Looker Studio environments, potentially breaching HIPAA compliance requirements.
Information Technology/IT
Cloud misconfiguration vulnerabilities in Google Looker Studio create cross-tenant data exposure risks affecting IT organizations managing multi-client cloud environments.
Government Administration
Zero-click SQL injection flaws enable unauthorized access to government databases through Google Cloud platforms, compromising sensitive administrative data integrity.
Sources
- New "LeakyLooker" Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Querieshttps://thehackernews.com/2026/03/new-leakylooker-flaws-in-google-looker.htmlVerified
- Google Cloud Platform (GCP) Zero-Click Cross-Tenant SQL Injection Vulnerability on Big Query in Looker Studio - Research Advisoryhttps://www.tenable.com/security/research/tra-2025-28Verified
- Google Cloud Platform (GCP) Zero-Click Cross-Tenant SQL Injection Vulnerability Through Stored Credentials in Looker Studio - Research Advisoryhttps://www.tenable.com/security/research/tra-2025-29Verified
- Google Cloud Platform (GCP) Cross-Tenant SQL Injection Vulnerability on Big Query Through Native Functions in Looker Studio - Research Advisoryhttps://www.tenable.com/security/research/tra-2025-27Verified
- Google Cloud Platform (GCP) Cross-Tenant Data Sources Leak With Hyperlinks in Looker Studio - Research Advisoryhttps://www.tenable.com/security/research/tra-2025-40Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to exploit cross-tenant vulnerabilities, thereby reducing the potential for unauthorized access and data exfiltration across cloud tenants.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit cross-tenant vulnerabilities would likely be constrained, reducing unauthorized access to databases.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges and execute arbitrary SQL queries would likely be constrained, reducing unauthorized database operations.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement across cloud tenants would likely be constrained, reducing unauthorized access to multiple datasets and projects.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish control over databases and issue commands would likely be constrained, reducing data manipulation and exfiltration.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data to external destinations would likely be constrained, reducing data loss.
The attacker's ability to modify or delete data would likely be constrained, reducing data integrity issues and operational disruptions.
Impact at a Glance
Affected Business Functions
- Data Analytics
- Business Intelligence
- Data Visualization
- Reporting
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive organizational data stored in Google Cloud Platform services such as BigQuery, Spanner, and Google Sheets.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement.
- • Deploy East-West Traffic Security controls to monitor and restrict internal traffic flows, mitigating lateral movement risks.
- • Utilize Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Regularly update and patch systems to address known vulnerabilities and reduce the attack surface.



