Metabase Incident Impacting Kilo Code Customer Data

August 9, 2026 14:50 UTC Update

We continue to investigate the impact to Kilo users from the Metabase incident.

Our investigation so far has confirmed that the Kilo Slackbot was impacted and a small subset of Kilo users on that feature had their Slack access token exposed. Out of an abundance of caution, we invalidated all Kilo Slackbot authentication tokens for these users. Affected Kilo Slackbot users were contacted.

For more information on reactivating Kilo Slackbot, please see the documentation: https://kilo.ai/docs/code-with-ai/platforms/slack#setupWe updated the Anaconda blog with more information on August 9, 2026 14:46 UTC.

On August 6, 2026, we were notified of a security incident at our business intelligence provider, Metabase. Kilo user information was in the database that was accessed through Metabase. According to logs of the incident provided by Metabase, an unknown actor accessed our customer records in Metabase, which included some Kilo users’ names, email addresses, and other data. Our analysis indicates that this incident did not expose Kilo customer payment information, and exposed data from only some Kilo users (not all).

The incident at Metabase occurred over a period of approximately 4 hours on August 2, 2026. Kilo was notified on August 6, 2026 . We immediately took steps to contain the incident, and began an internal investigation which remains ongoing. We are sharing this update as we have it, and will share others (including updates to specific affected users, as we can) on a followup basis as soon as we have additional results from our investigation. Please watch our blog and website for additional updates.

We (Kilo and Anaconda, which recently acquired Kilo), are committed to transparency and sharing action-oriented, helpful information around this incident, as we obtain it, and further updates will be coming. Please continue to check the Anaconda blog post for further updates.

For more detailed information about the Metabase incident, please refer to the Metabase security alert.

The Anaconda blog will be updated as our investigation continues.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论