Dear customers and partners,
We are informing you of a security incident that has affected certain personal data. The incident concerns Metabase, an open-source data visualisation tool that we have hosted for several months for reporting purposes. The details are set out below.
Data from a marketing report hosted on Metabase was extracted by the attacker and published. Depending on the record, this data includes: last name, first name, email address, company or organisation, job title, user ID, the IP address used when the account was created and, in some cases, telephone number and LinkedIn profile address.
We have contacted directly, by email, every individual whose data appears in the published files. If you have not received such a message from us, your data is not among the records concerned.
If you have any doubt, our Data Protection Officer can confirm your situation at dpo@timetonic.com.
The Metabase environment is isolated from our main platform. The TimeTonic platform itself, your application data and all our other services are unaffected. The scope of this incident is limited to Metabase.
No attachments, no PDF or DOCX documents, and no message subjects or contents held in your TimeTonic data were extracted.
TimeTonic passwords were never compromised. Passwords are not stored in Metabase. They are also held exclusively in hashed and salted form. No action on your part is required in this respect.
A critical vulnerability affecting Metabase (CVE-2026-72898, rated 10/10) was made public on 6 August 2026. It allows administrator-level access to the tool without any username or password. Exploited through automated attacks, it has affected a large number of services in France and worldwide.
Our Metabase instance was among them in August 2026.
The extracted data was published on the evening of 25 August 2026 on a specialist forum. We became aware of it on 26 August and intervened immediately.
As soon as we became aware of the incident: full isolation of our Metabase instance, revocation of every access created by the attacker, upgrade to a patched version of Metabase, and rotation of all technical secrets.
Our Metabase reporting instance is no longer exposed publicly on the internet. Access for authorised users remains suspended while we complete our verifications and implement any additional protective measures. It will be restored afterwards, and we will inform you when it is.
We are filing a criminal complaint and have notified the CNIL, the French data protection authority. We are continuously monitoring data publication and resale sites, and we have durably strengthened our security monitoring and patching procedures.
The main risk associated with the published data is targeted phishing. The information concerned : identity, job title, organisation, contact details and makes it possible to construct highly credible fraudulent approaches by email, SMS, telephone or professional networks, impersonating TimeTonic or one of your usual contacts.
We encourage you to be especially vigilant with any unexpected message requesting information, a payment or urgent action, and to raise awareness among your teams accordingly.
TimeTonic will never ask you for your password, by email or by telephone.
Our Data Protection Officer can be reached at dpo@timetonic.com for any question relating to this incident or to your data. You also have the right to lodge a complaint with the CNIL (www.cnil.fr).
We fully appreciate the seriousness of this incident and we apologise for it. All our teams are mobilised to support you and to draw every lesson from what has happened. We remain entirely at your disposal.
Jean-Michel Durocher
Chief Executive Officer, TimeTonic