August 20, 2026

Notice Regarding a Third-Party Security Incident

Avatar photo Written by
Max 3 min read
Share this post
Get Krisp for Free
We are sharing information about a security incident involving Metabase, a third-party analytics platform used by Krisp.

On August 6, 2026, Metabase published a security advisory concerning a critical vulnerability affecting certain versions of its software. According to Metabase, the vulnerability could allow an unauthenticated remote attacker to gain administrative access to an affected Metabase instance and, from there, potentially access and export data available through that instance. Metabase has reported that this vulnerability was actively exploited.

Our investigation determined that our Metabase environment was affected and that an unauthorized party accessed and exfiltrated certain data from the environment.

For those interested in the technical details of the vulnerability, affected versions, and Metabase’s recommended remediation, please refer to the official Metabase security advisory.

What information was involvedBased on our investigation, the affected personal information was limited to:

  • email addresses; and
  • associated team/workspace names.

The incident did not expose or compromise customer content, including audio or transcripts. It also did not expose financial or payment information, authentication credentials, or passwords.

The affected information does not by itself provide access to Krisp accounts or enable transactions or other financial activity.

Krisp does not store user passwords. Authentication is handled through Google Sign-In, email verification codes, or SAML-based Single Sign-On (SSO), depending on the authentication method configured for the account.

What we have done

  • Following identification of the incident, we took immediate steps to secure the affected environment and investigate the scope of the unauthorized access.
  • We have reviewed the incident from security, privacy, and regulatory perspectives and have taken appropriate measures to address the incident and mitigate potential risks.
  • We are notifying affected customers and other relevant parties where required and continue to monitor the situation.

What this means for affected users

  • Based on our investigation and the nature of the information involved, no customer content, including audio or transcripts, was accessed or compromised as part of this incident. The exposed information does not by itself provide access to Krisp accounts or enable financial activity.
  • However, email addresses and associated team/workspace information could potentially be used to make phishing or other social-engineering communications appear more credible.

As a precaution, we recommend remaining attentive to unexpected emails or messages, particularly those asking you to follow unfamiliar links, provide authentication information, or take urgent action.If you receive a communication that appears to come from Krisp and are uncertain about its authenticity, please contact us directly at [email protected].

Our commitmentWe take the security and privacy of the information entrusted to us seriously. We recognize the importance of communicating transparently when an incident involving that information occurs, including when it results from a vulnerability in third-party software.

We have taken appropriate measures in response to the incident and will continue to monitor the situation. If our assessment materially changes or we identify additional information relevant to affected users, we will update this notice accordingly.If you have questions about this incident or the processing of your personal data, please contact [email protected].

Get Krisp for Free

You're one step away from
supercharging your online meeting!

background for toggle
Get started