Tally Forms has sent an email to customers notifying them of a data breach that exposed email addresses and password hashes after an attacker compromised a third-party analytics platform it uses.
According to Tally Co-founder Filip Minev, the attacker gained unauthorized access to its Metabase analytics environment on August 3 by exploiting a previously unknown zero-day vulnerability in the software.
The attacker accessed customer email addresses and cryptographic password hashes. However, Tally says customer forms and submitted responses were not affected because they are stored in a separate database.
Flip says Metabase notified Tally of the vulnerability on August 6, and access to the affected system was shut down the same day.
As part of its response, Tally has:
- Changed internal passwords and security keys.
- Removed Metabase’s access to its database.
- Confirmed that Metabase has patched the vulnerability.
- Supported an ongoing investigation by an external cybersecurity firm.
- Reported the incident to the Belgian Data Protection Authority.
Tally also reviewed its authentication logs and says it found no evidence that the exposed information was used to access customer accounts.
While Tally says no immediate action is required, it recommends changing your password, enabling two-factor authentication (2FA), and watching out for phishing emails that claim to be from Tally.
