New York, October 8, 2026 / PRNewswire / -- Photon is notifying individuals whose personal information may be involved in a cybersecurity incident. This statement aims to inform the potentially affected individuals about the situation regarding this incident, the Photon measures that have been taken, as well as the resources available to assist and protect them.
What happened?
Photon indicates that on August 21, 2026, the company became aware that an unauthorized third party took advantage of a previously unknown security vulnerability (sometimes referred to as a "zero-day" vulnerability) in Metabase to access certain data. Metabase is a third-party application used by Photon in a self-hosted manner for business intelligence, product metrics, and customer dashboards.
The company stated that upon becoming aware of the incident, it immediately took measures to protect the application and hired a team of cybersecurity experts to assess, contain, and fix the issue. The investigation revealed that some data may have been accessed without authorization. After a comprehensive review of the affected data, which was completed on September 4, 2026, the company confirmed that certain personal information might have been compromised. Photon indicates that there is currently no evidence to suggest that any potentially affected information has been misused or that there were attempts to do so.
What information is involved?
Photon indicates that social security numbers and financial information were not affected by this incident, as the company does not collect or store such information. The investigation found that some individuals' names, addresses, phone numbers, dates of birth, and prescription drug information were exposed in this incident. The company specifically noted that the types of information affected varied from person to person, and not all of the aforementioned information for each individual was exposed.
What measures is the company taking?
Photon indicates that the company takes its responsibility for protecting information seriously and expresses regret for the concerns that may arise from this incident. Upon discovering the incident, Photon promptly initiated response measures, including conducting a comprehensive investigation with the assistance of cybersecurity experts, to confirm the security of its Metabase environment. The company states that it is continuously reviewing and revising its technical protection measures and making improvements to reduce the likelihood of similar incidents occurring in the future. In addition, Photon indicates that it will be committed to helping those who may have been affected by this incident.
The company stated that it has sent notification letters to individuals who may be affected, explaining the steps they can take to protect their own information. In response to these concerns and to mitigate the potential risks of exposure or damage that may arise after this incident, Photon has arranged free credit monitoring services and identity theft protection services for all individuals who may be affected, with the service period lasting for 12 to 24 months. Individuals do not need to bear any costs. Photon recommends that affected individuals register for these services and follow the recommendations in the notification letters to ensure that their information is protected.
More information
Individuals seeking more information or having questions about this incident can call the dedicated hotline at 1-844-772-5746 from 8:00 a.m. to 8:00 p.m. Eastern Time, Monday through Friday (excluding holidays).











