cd /news/ai-tools/metabase-incident-impacting-kilo-cod… · home topics ai-tools article
[ARTICLE · art-107792] src=blog.kilo.ai ↗ pub= topic=ai-tools verified=true sentiment=↓ negative

Metabase Incident Impacting Kilo Code Data

An unknown actor accessed Kilo user records through a Metabase security incident on August 2, 2026, exposing names, email addresses, and other data for a subset of Kilo users, but not payment information. Kilo, acquired by Anaconda, invalidated all Kilo Slackbot authentication tokens after confirming the Slackbot was impacted, and affected users were contacted. The investigation is ongoing, and updates are being posted on the Anaconda blog.

read2 min views11 publishedAug 7, 2026
Metabase Incident Impacting Kilo Code Data
Image: Blog (auto-discovered)

August 14, 2026 23:19 UTC Update

We updated the Anaconda blog with more information on August 14, 2026 21:30 UTC. August 9, 2026 14:50 UTC Update

We continue to investigate the impact to Kilo users from the Metabase incident.

Our investigation so far has confirmed that the Kilo Slackbot was impacted and a small subset of Kilo users on that feature had their Slack access token exposed. Out of an abundance of caution, we invalidated all Kilo Slackbot authentication tokens for these users. Affected Kilo Slackbot users were contacted.

For more information on reactivating Kilo Slackbot, please see the documentation: [https://kilo.ai/docs/code-with-ai/platforms/slack#setup](https://kilo.ai/docs/code-with-ai/platforms/slack)** **We updated the

[Anaconda blog](https://www.anaconda.com/metabase-incident-impacting-kilo-code-customer-data)with more information on August 9, 2026 14:46 UTC.

On August 6, 2026, we were notified of a security incident at our business intelligence provider, Metabase. Kilo user information was in the database that was accessed through Metabase. According to logs of the incident provided by Metabase, an unknown actor accessed our customer records in Metabase, which included some Kilo users’ names, email addresses, and other data. Our analysis indicates that this incident did not expose Kilo customer payment information, and exposed data from only some Kilo users (not all).

The incident at Metabase occurred over a period of approximately 4 hours on August 2, 2026. Kilo was notified on August 6, 2026 . We immediately took steps to contain the incident, and began an internal investigation which remains ongoing. We are sharing this update as we have it, and will share others (including updates to specific affected users, as we can) on a followup basis as soon as we have additional results from our investigation. Please watch our blog and website for additional updates.

We (Kilo and Anaconda, which recently acquired Kilo), are committed to transparency and sharing action-oriented, helpful information around this incident, as we obtain it, and further updates will be coming. Please continue to check the Anaconda blog post for further updates.

For more detailed information about the Metabase incident, please refer to the [Metabase security alert](https://www.metabase.com/blog/security-update).

[The Anaconda blog](https://www.anaconda.com/metabase-incident-impacting-kilo-code-customer-data) will be updated as our investigation continues.
── more in #ai-tools 4 stories · sorted by recency
── more on @metabase 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/metabase-incident-im…] indexed:0 read:2min 2026-08-07 ·