Avviso relativo a un incidente di sicurezza - Settembre 2026

Annunci

Squadra AhaSlides · XNUMX€ 09 settembre, 2026 · XNUMX€ 3 min leggere

On 7 September 2026, we discovered that an unauthorised party had accessed one of our internal systems by exploiting a vulnerability (CVE-2026-72898) in Metabase, a third-party analytics tool we use internally. We cut off the access immediately and began an investigation. It found that the intruder had access between 12 August and 7 September 2026, and that our user account and invoice data were extracted.

This affects all registered accounts on AhaSlides.com. AhaSlides.eu, our separate deployment serving Skoletube, runs on isolated infrastructure and was not affected.

Below is exactly what was exposed and what we recommend you do.

What was exposed

  • Indirizzi email.
  • IP address and city at the time of signup.
  • Invoice information: name, IP address at the time of purchase, and what you have purchased.
  • Passwords, in hashed and salted form (PBKDF2-HMAC-SHA512). Hashes cannot be directly reversed to recover your password, but a weak or common password could still be matched through brute force.
  • Billing addresses for 0.12% of users, due to a legacy field that was still stored in our database. We will contact these affected users individually by email.

What was not exposed

  • Credit card and payment card numbers. We never store these.
  • Plain-text passwords. We never store these.

What we're asking you to do

  1. Please reset your AhaSlides password if you have one.
  2. If you use the same password on other services, please change it there as well. We'd rather you didn't take the chance.
  3. If you sign in through your organisation's identity provider or single sign-on (Google, Microsoft, Okta, etc.): your password is not stored in AhaSlides, so there is nothing to reset. The rest of this notice still applies to you.

Attenzione al phishing

Because the exposed data includes names, email addresses and purchase history, phishing emails pretending to be from us may look more convincing than usual. We will never ask for your password by email. Billing emails come from Stripe, our payment provider - but if any email asks you to confirm payment details, you never need to click it: type ahaslides.com into your browser and check your billing page directly.

Quello che abbiamo fatto

  • Patched Metabase to a secure version and revoked all unauthorised access.
  • Restricted Metabase access to an approved IP allowlist.
  • Reviewed our wider access controls and logs for any further sign of intrusion.
  • Notified the relevant data protection authorities.
  • Improved our vulnerability alert system so that we are immediately informed of new critical security vulnerabilities that are relevant to our system.

Our wider security work

Security at AhaSlides goes beyond this incident. We conduct independent penetration testing and are currently undergoing independent audits for SOC 2 and ISO/IEC 27001 certification. We will publish the changes we make as a result of this incident.

Domande

If you have questions about this notice or about your account, contact us at security@ahaslides.com. We'll keep this page updated if anything material changes.

We're sorry this happened, and we appreciate your trust.

Chau Hoang
Direttore Tecnico
Ah diapositive