Metabase Incident Impacting Kilo Code Customer Data
On August 6, 2026, we were notified of a security incident at our business intelligence provider, Metabase. Kilo user information was in the database that was accessed through Metabase. According to logs of the incident provided by Metabase, an unknown actor accessed our customer records in Metabase, which included some Kilo users’ names, email addresses, and other data. Our analysis indicates that this incident did not expose Kilo customer payment information, and exposed data from only some Kilo users (not all).
The incident at Metabase occurred over a period of approximately 4 hours on August 2, 2026. Kilo was notified on August 6, 2026 . We immediately took steps to contain the incident, and began an internal investigation which remains ongoing. We are sharing this update as we have it, and will share others (including updates to specific affected users, as we can) on a followup basis as soon as we have additional results from our investigation. Please watch our blog and website for additional updates.
We (Kilo and Anaconda, which recently acquired Kilo), are committed to transparency and sharing action-oriented, helpful information around this incident, as we obtain it, and further updates will be coming. Please continue to check the Anaconda blog post for further updates.
For more detailed information about the Metabase incident, please refer to the Metabase security alert.
This blog will be updated as our investigation continues.
