Skip to main content
Jump to a category page

Stocksy Notifies Users After a Maximum-Severity Zero-Day Hit Its Analytics Vendor, Metabase

A security flaw rated the maximum possible severity score, 10 out of 10, let hackers slip into a tool that had access to Stocksy user data. Stocksy says the intrusion stayed contained to that one vendor, but the same vulnerability has already hit other companies too.

Stocksy uses a business intelligence platform called Metabase to analyze its operational data. On August 3, 2026, Metabase discovered that its cloud service had been attacked through a previously unknown flaw, a “zero-day” vulnerability. Metabase cut off the attacker’s access, patched the flaw, and brought in outside forensics help. On August 6, 2026, Metabase told Stocksy that its own instance had been reached, and Stocksy confirmed that a database connected to that instance was accessed.

A Vulnerability Rated the Maximum Severity Score, and Stocksy Isn’t the Only Company Hit

Security researchers have identified the underlying flaw as a SQL injection vulnerability in an unauthenticated Metabase endpoint, rated a CVSS score of 10.0, the maximum possible severity rating a vulnerability can receive, according to BleepingComputer, The Hacker News, and SecurityWeek. Metabase’s own cloud platform was compromised through this flaw on August 3, 2026, and at least two other companies, Framework and Tally, have separately disclosed data theft linked to the same vulnerability. This wasn’t a targeted attack on Stocksy specifically; it was a critical flaw in shared infrastructure that a number of companies relying on Metabase are now dealing with.

What Information Was Exposed?

Per Stocksy’s own notice, the information accessed for affected accounts was limited to:

  • Email Address
  • Password

Stocksy’s notice states that no payment card numbers, banking or payout details, government identification, license history, or order records were part of the data accessed. Users who only ever signed in through Facebook or Google, without a Stocksy-specific password, had no password exposed.

What Is Stocksy Doing?

Stocksy reset the password on every account, ended all active sessions, rotated the credentials on every database connected to its Metabase instance, and audited its administrator accounts, confirming nothing had been added, removed, or altered. The company also says it verified the attacker’s activity stayed inside Metabase and did not extend into Stocksy’s broader network. Because no financial or government-ID data was involved, Stocksy is not offering credit monitoring; its remedy here is centered on password resets and account security rather than identity theft protection.

Your Information Is at Risk, Even With Hashing

A hashed and salted password is far more protected than one stored as plain text, and Stocksy deserves credit for handling that part correctly. But Stocksy’s own notice flags the real remaining risk directly: if you used your Stocksy password on any other site, that reused password is now something an attacker could try elsewhere. Password reuse is consistently the most common way a limited exposure like this one turns into an actual account compromise on a completely different site. There’s also an ordinary phishing risk any time a real incident like this becomes public; watch for emails referencing the breach that ask you to click a link or confirm account details.

Do You Have Legal Options?

Companies that give a third-party vendor broad access to user data have a legal duty to oversee that access responsibly, and to notify affected users when that vendor is compromised. Stocksy’s own notice states it is now restricting its analytics vendor’s access to specific fields rather than whole tables going forward, a change that suggests the prior level of access was broader than necessary.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice from Stocksy.

FAQ

Who is affected by the Stocksy data breach?

Stocksy account holders whose account data was reachable through the company’s Metabase instance. Stocksy has not disclosed a total number of affected accounts.

What information was exposed?

Email addresses and passwords in hashed and salted form for accounts that had one. Payment information, banking or payout details, government ID, license history, and order records were not accessed, per Stocksy’s own notice.

Is my password at risk if it was hashed and salted?

A hashed, salted password is much harder to reverse than a plain-text one, but it isn’t risk-free, and it does nothing to protect you on other sites where you reused the same password. Change your Stocksy password and any other account using the same one.

Do I have a legal claim?

Companies that grant vendors access to user data have a legal duty to oversee that access and to notify affected users when a vendor is compromised. If you received a notice from Stocksy, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 for a Free Case Review.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now