On August 6, 2026, Kilo Code (recently acquired by Anaconda) was notified of a security incident at its business intelligence provider, Metabase. Kilo uses Metabase for analyzing data to improve the Kilo user experience. Kilo user information was in the database that was accessed through Metabase. According to logs of the incident provided by Metabase, an unknown actor accessed our customer records in Metabase, which included some Kilo users’ names, email addresses, and other data. Our analysis indicates that this incident did not expose Kilo customer payment information, and exposed data from only some Kilo users (not all). 

The Metabase incident affected only users of Kilo Code. Anaconda customers who were not Kilo users were unaffected. 

The incident at Metabase occurred over a period of approximately 4 hours on August 2, 2026. Kilo was notified on August 6, 2026. We immediately took steps to contain the incident, and began an internal investigation to fully understand the impact to affected Kilo users, which will  remain ongoing. We will be sharing updates as we have them, starting with this blog, and will continue to share updates (including updates to specific affected users) until we complete our investigation.  

Anaconda and the Kilo team are committed to transparency and sharing action-oriented, helpful information around this incident, as we obtain it. Please watch this blog for additional updates.

For more detailed information about the Metabase incident, please refer to the Metabase security alert.