Lego Certified Stores South Africa emailed customers on Friday to say their email addresses and mobile numbers had been accessed by an unauthorised party. No banking, card or password data was involved.
The breach did not happen at Lego, and it did not happen at Marsello, the company that runs its loyalty and marketing programme. It happened inside Metabase, a reporting tool Marsello uses internally, which was hit by a zero-day on 5 August.
Interesting insights on Lego South Africa data breach
The vulnerability is about as severe as they come. It is an unauthenticated SQL injection in a publicly reachable password-reset endpoint, rated CVSS 10.0, affecting Metabase versions 1.58 and above. It hands an attacker full administrator access with no credentials, plus the stored passwords for every database the tool connects to.
Metabase detected the attack on its own cloud platform on 3 August and shipped a fix on 6 August, which Marsello applied immediately. Marsello only confirmed to Lego on 14 August that data had actually been taken. Framework, Tally, n8n and Checkly have disclosed related breaches. Wiz estimates roughly 2,500 Metabase instances are reachable from the open internet, and public exploit code appeared on 10 August.
What others are saying about Lego South Africa data breach
MyBroadband reported the notification and Lego's warning that affected customers should expect a rise in phishing messages appearing to come from legitimate businesses. Help Net Security has tracked the widening list of companies disclosing breaches through the same flaw. SecurityWeek notes Metabase shipped patches across six separate release branches.
You are liable for your vendor's vendor
Count the layers. Lego's customers trusted Lego. Lego trusted Marsello. Marsello trusted Metabase. The failure happened four layers down, and the apology email still went out under Lego's name, because under POPIA the responsible party stays responsible no matter how many operators sit in the chain.
Most SA founders cannot name every subprocessor their loyalty, SMS or analytics vendors rely on. In the same week, Toyota SA customers were exposed through an SMS provider. The fix is unglamorous: ask each vendor for its subprocessor list, and put a contractual notification deadline in writing. Nine days passed between exploit and email. That was not Lego's fault. It was still Lego's letter.
You might also like our piece on the stolen browser cookies circulating in SA, why AI financial crime in SA is outrunning board oversight, and how the SA spam call rules changed what you owe your marketing list.
Get more SA tech and business news and subscribe to The Open Letter.


