Cypress Metabase Cloud data incident

Cypress reported unauthorized queries against its Metabase Cloud instance.

Last modified

Summary

  • Environment: Metabase Cloud analytics instance
  • Operational impact: Cypress reported test execution was unaffected
  • Financial impact: No incident cost established in the reviewed evidence
  • Record status: Developing record. Reviewed October 7, 2026; updated as evidence emerges.

What happened

Cypress reported unauthorized queries against its Metabase Cloud instance. [2]

Impact

Accessible information included account data, build metadata and, for some customers, tokens and recorded test content. [2]

Cypress said test execution and results were unaffected. [2]

Timeline

  1. Unauthorized queries

    Attacker activity reported by Metabase to Cypress.

    [2]
  2. Cypress notified

    Metabase informed Cypress.

    [2]
  3. Customer notifications

    Affected organizations were notified.

    [2]
  4. Briefing updated

    This briefing was last reviewed and updated on October 7, 2026.

Threat Group & Attack Vector

Cypress attributed access to a previously unknown Metabase vulnerability. [2]

Metabase described SQL injection that created administrative sessions. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Cypress rotated credentials, revoked sign-in authorizations and commissioned independent forensic review. [2]

Metabase patched Cloud instances and released fixes on August 6. [3]