← Tally (tally.so)

2026 Tally (tally.so) — Metabase analytics compromise; emails + password hashes (Aug 3)

2026 Unknown records affected Share on X

Data compromised

User email addresses and password hashes (cryptographic one-way hashes per Tally — algorithm/salting not confirmed publicly at indexing). Form contents and submitted answers stored separately and not reached per company notice. Count unpublished.

Technical writeup

Company-confirmed Metabase analytics breach — Popular form builder Tally (tally.so) notified users that its Metabase analytics environment was compromised on August 3, 2026 in the same zero-day campaign Metabase disclosed (unauthenticated SQLi giving admin access to customer instances). Tally told users attackers reached email addresses and password hashes, stating hashes are one-way and cannot be turned back into passwords, and that forms and submitted answers are stored separately and were not reached. BleepingComputer asked which hashing algorithm was used and whether hashes were salted; no public answer at indexing time — users should still rotate passwords and enable MFA. Distinct from Indian ERP vendor Tally Solutions (tally-solutions) already in the catalog. recordsAffected 0 pending a user census.

Root cause

Compromise of Tally’s Metabase analytics environment on August 3, 2026 via the Metabase unauthenticated SQL injection zero-day exploited against Cloud/self-hosted instances ≥1.58.

References