Security Incident Affecting Our Metabase Reporting Environment

Account data was exposed through our Metabase tool. Here is what was affected and what was not.
Jean-Michel Durocher
August 31, 2026
Share it 🚀

Dear customers and partners,

We are informing you of a security incident that has affected certain personal data. The incident concerns Metabase, an open-source data visualisation tool that we have hosted for several months for reporting purposes. The details are set out below.

What data was affected

Data from a marketing report hosted on Metabase was extracted by the attacker and published. Depending on the record, this data includes: last name, first name, email address, company or organisation, job title, user ID, the IP address used when the account was created and, in some cases, telephone number and LinkedIn profile address.

Who is affected

We have contacted directly, by email, every individual whose data appears in the published files. If you have not received such a message from us, your data is not among the records concerned.

If you have any doubt, our Data Protection Officer can confirm your situation at dpo@timetonic.com.

What was not affected

The Metabase environment is isolated from our main platform. The TimeTonic platform itself, your application data and all our other services are unaffected. The scope of this incident is limited to Metabase.

No attachments, no PDF or DOCX documents, and no message subjects or contents held in your TimeTonic data were extracted.

TimeTonic passwords were never compromised. Passwords are not stored in Metabase. They are also held exclusively in hashed and salted form. No action on your part is required in this respect.

What happened

A critical vulnerability affecting Metabase (CVE-2026-72898, rated 10/10) was made public on 6 August 2026. It allows administrator-level access to the tool without any username or password. Exploited through automated attacks, it has affected a large number of services in France and worldwide.

Our Metabase instance was among them in August 2026.

The extracted data was published on the evening of 25 August 2026 on a specialist forum. We became aware of it on 26 August and intervened immediately.

What we have done

As soon as we became aware of the incident: full isolation of our Metabase instance, revocation of every access created by the attacker, upgrade to a patched version of Metabase, and rotation of all technical secrets.

Our Metabase reporting instance is no longer exposed publicly on the internet. Access for authorised users remains suspended while we complete our verifications and implement any additional protective measures. It will be restored afterwards, and we will inform you when it is.

We are filing a criminal complaint and have notified the CNIL, the French data protection authority. We are continuously monitoring data publication and resale sites, and we have durably strengthened our security monitoring and patching procedures.

Risks and our recommendations

The main risk associated with the published data is targeted phishing. The information concerned : identity, job title, organisation, contact details and makes it possible to construct highly credible fraudulent approaches by email, SMS, telephone or professional networks, impersonating TimeTonic or one of your usual contacts.

We encourage you to be especially vigilant with any unexpected message requesting information, a payment or urgent action, and to raise awareness among your teams accordingly.

TimeTonic will never ask you for your password, by email or by telephone.

Your contacts and your rights

Our Data Protection Officer can be reached at dpo@timetonic.com for any question relating to this incident or to your data. You also have the right to lodge a complaint with the CNIL (www.cnil.fr).

We fully appreciate the seriousness of this incident and we apologise for it. All our teams are mobilised to support you and to draw every lesson from what has happened. We remain entirely at your disposal.

Jean-Michel Durocher
Chief Executive Officer, TimeTonic

Create your business apps easily with NoCode
Start now

Thirsty for more ?

These other blog posts may be interesting for you