Metabase attack steals Framework and Tally customer data
Metabase said on August 27 that the flaw compromised under 3% of its cloud customers, plus some self-hosted users. New disclosures tied the flaw to a ShipMonk breach that exposed data from 80,689 Trezor customers. Mathspace also confirmed that attackers entered its unpatched self-hosted Metabase system and downloaded records for 1,079,819 people on August 27. Mathspace took the system offline on September 3 and was completing recovery checks as of September 8. ShinyHunters sent extortion emails to ShipMonk and listed Metabase on its leak site, but no victim or agency has confirmed who carried out the attacks.
- Started
- Aug 3, 2026
- Latest activity
- Sep 8, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- United States, Belgium
- Sectors
- Technology
- Scale
- Metabase Cloud and five customer organizations: Framework, Tally, Kilo Code, n8n, and Checkly
Current status
A September 10 Information Age report said Mathspace had no evidence that the stolen data was published or misused, and reported no service restoration or closure.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Impact
Framework said names, email addresses, phone numbers, login IP addresses, company names, and billing and shipping addresses were stolen. Tally reported exposed email addresses and password hashes. Kilo said some users' names, emails, billing addresses, locations, prompts, and other user data may have been exposed. A small set of Slack access tokens was exposed. n8n confirmed access to 12 sensitive records, including five with hashed cloud passwords, and said 62 more name and email records may have been accessed. Checkly said values stored directly in check settings, hashed tracing API keys, and encrypted integration tokens were accessed or may have been exposed. Checkly found no access to its production platform. ShipMonk's breach exposed names, email addresses, phone numbers, shipping addresses, cities, and order numbers belonging to 80,689 Trezor customers.
What to do
Framework customers should watch for targeted scams. Tally and contacted n8n users should change reused or exposed passwords. Kilo users should request their data export, review their session history, watch for scams, and replace passwords or keys that may have appeared in prompts. Checkly customers should replace credentials stored directly in check settings, replace tracing API keys, review protected systems for misuse, and reconnect affected integrations. Trezor customers who received a notice should watch for scam emails, calls, and letters. They should never share their wallet backup or enter it on a website.
Timeline
-
Sep 10, 2026
The Australian Computer Society's Information Age reported that Mathspace had no evidence the stolen data was published, distributed, sold, or otherwise misused. It reported no service restoration or closure.
Containedia.acs.org.au -
Sep 8, 2026
Mathspace said it had finished identifying affected accounts and records. Its reporting system remained offline while recovery checks continued.
Containedblog.mathspace.co -
Sep 6, 2026
Mathspace began sending notices to affected students, parents, guardians, teachers, and staff.
Containedblog.mathspace.co -
Sep 4, 2026
Trezor said ShipMonk's breach exposed data from another 67,000 US customers, bringing the confirmed total to 80,689.
Containedtrezor.io -
Sep 3, 2026
Mathspace confirmed the breach, took its Metabase system offline, disabled its database access, replaced passwords, and revoked its Metabase API keys.
Containedblog.mathspace.co -
Aug 27, 2026
Attackers downloaded information from Mathspace's Australian reporting database after entering its unpatched self-hosted Metabase system.
Activeblog.mathspace.co -
Aug 27, 2026
Metabase said under 3% of its cloud customers were compromised and that some self-hosted users were also affected. It released another set of security changes in version 63.13.
Containedmetabase.com -
Aug 18, 2026
Kilo added a data export limited to categories that may have been accessed during the Metabase incident.
Containedanaconda.com -
Aug 14, 2026
Anaconda said it had finished notifying affected Kilo users. It said further investigation could identify more affected users.
Containedanaconda.com -
Aug 12, 2026
CSO Online identified five affected Metabase customers: Framework, Tally, Kilo Code, n8n, and Checkly.
Containedcsoonline.com -
Aug 12, 2026
Checkly updated its notice after finding that the attacker had read its analytics data for about 26 minutes. Checkly said its production platform was not accessed.
Containedchecklyhq.com -
Aug 11, 2026
CISA added CVE-2026-72898 to its Known Exploited Vulnerabilities catalog with an August 14 remediation deadline.
Containedcisa.gov -
Aug 11, 2026
n8n said later analysis confirmed access to 12 sensitive records, including five with hashed cloud passwords, while 62 more name and email records may have been accessed.
Containedblog.n8n.io -
Aug 9, 2026
Anaconda said an unknown actor accessed Kilo Code customer records and that some users may have had personal data or prompts exposed. Kilo invalidated Slack access tokens for an affected group.
Containedanaconda.com -
Aug 7, 2026
Framework confirmed that the breach affected all customers and did not include payment information.
techcrunch.com -
Aug 6, 2026
Metabase disclosed the attack, blocked the route used by the attacker, and patched its cloud service.
Containedmetabase.com -
Aug 3, 2026
The attacker entered Metabase Cloud environments used by Framework and Tally and accessed customer data.
Activebleepingcomputer.com
Sources
- Security update available for Metabase - Please upgrade now Metabase Aug 6, 2026
- SQL injection using an unauthenticated endpoint leading to admin access GitHub Aug 6, 2026
- Metabase SQLi zero-day exploited in customer data-theft attacks BleepingComputer Aug 7, 2026
- Computer maker Framework notifies 'all customers' of a data breach TechCrunch Aug 7, 2026
- Metabase zero-day exploited in wild allows admin access without authentication The Hacker News Aug 8, 2026
- Metabase patches vulnerability exploited as zero-day SecurityWeek Aug 10, 2026
- Metabase Incident Impacting Kilo Code Data Anaconda Aug 9, 2026
- Metabase security incident update n8n Aug 11, 2026
- Known Exploited Vulnerabilities Catalog: CVE-2026-72898 CISA Aug 11, 2026
- Metabase Security Incident Checkly Aug 12, 2026
- Metabase SQLi exploit grants attackers total access CSO Online Aug 12, 2026
- A Field Guide to Understanding Your Kilo Data Export Kilo Blog Aug 18, 2026
- ShinyHunters claims Metabase breach days after zero-day exposes 100K+ organizations Cybernews Aug 11, 2026
- August 2026 Security Vulnerability: What happened? Metabase Aug 27, 2026
- Recent customer data exposed in shipping provider incident Trezor Sep 4, 2026
- Mathspace data breach: what happened and what affected users should know Mathspace Sep 8, 2026
- Trezor data breach impact now reaches 81,000 customers BleepingComputer Sep 7, 2026
- Mathspace discloses data breach affecting over 1 million people BleepingComputer Sep 7, 2026
- More than 1m caught in Mathspace data breach Information Age Sep 10, 2026
Related reports
- Metabase zero-day steals database passwords Aug 10, 2026
- Metabase zero-day lets attackers take over your business data Aug 10, 2026
- Metabase flaw gives attackers administrator access Aug 8, 2026
- Metabase data leak from zero-day hack Aug 8, 2026