Hi Testing,
On 7 September 2026 we discovered that an unauthorised party had accessed Metabase, a third-party analytics tool we use internally. We cut off the access immediately and began an investigation, which found that user account and invoice data were extracted.
What happened
We have evidence that the following data was extracted:
Card details were not reached. Those are held by Stripe and weren't part of this incident. There was never a plain-text password to take, because we don't store one.
What we've done
We patched Metabase the same day. We've reviewed our wider access controls and logs for any other sign of intrusion, and improved our alerting so we hear about critical vulnerabilities immediately. We've reported this to the data protection authorities in Singapore, the Netherlands and the United Kingdom.
What this means for this account
The main risk is phishing. Because the name, email address and purchase history on this account were taken, messages may arrive that look like they came from AhaSlides but didn't. We'll never email a link asking anyone to sign in or to confirm payment details.
What we suggest
Please change the AhaSlides password for this account, and change it anywhere else the same password is used. A hash can't be reversed, but a weak or common one could still be cracked. If this account signs in with Google, Microsoft or single sign-on, we don't hold a password for it and there's nothing to reset.
We also run independent penetration testing and are partway through SOC 2 and ISO/IEC 27001 audits, and we'll publish whatever else changes because of this.
Our full notice has the dates, the technical detail and what we've reported.
I'm sorry we put you in this position. If you've got questions, just reply to this email and we'll answer.
Sincerely,
Chau Hoang
VP of Engineering, AhaSlides