Security notice: third-party breach claims.
On 25 August 2026, bitbybit Studio became aware of a security breach affecting one of its third-party analytics vendors, and initiated its incident-response process. As published on our status page, bitbybit has not confirmed that any bitbybit systems or customer information were affected, and any potential impact identified in the initial review would be limited to messaging services. The self-hosted third-party analytics component identified during that review was removed from our environment, and we published that remediation was complete on 30 August 2026.
Separately, claims have circulated on third-party websites and cybercrime forums — including material using the identifier “DATABASE-2026-bitbybit-studio-25M” and figures such as 25 million records. Those labels, dataset sizes, and attack-path descriptions originate from external sources. bitbybit Studio does not adopt them as verified findings.
This page is bitbybit Studio’s dated first-party record of both. Live operational state is maintained on the status page; our standing security practices are described on theSecurity & Trust page.
What happened, and when
The record below restates what bitbybit published on its public status page as events occurred. It is reproduced here so the full sequence can be read in one place.
- 25 August 2026
Awareness
bitbybit became aware of a security breach affecting one of its third-party analytics vendors.
- 26 August 2026
Incident response and public disclosure
bitbybit initiated its incident-response process and began investigating the scope of the breach and any potential impact on bitbybit systems and customer information, publishing the first update on its public status page. Based on that initial review, any potential impact would be limited to messaging services. bitbybit had not confirmed that any bitbybit systems or customer information were affected. Services remained operational.
- 29 August 2026
Third-party claims addressed
Following claims circulating on third-party websites and cybercrime forums, bitbybit published this notice together with its Security & Trust page.
- 30 August 2026
Remediation complete
The self-hosted third-party analytics component identified during the review was removed from the bitbybit environment, and additional precautionary hardening was applied to related systems and access.
What bitbybit Studio does not adopt
Third-party coverage has attached a number of specific figures and characterisations to bitbybit Studio. Repeating a claim in order to address it is not the same as confirming it. Each of the following originates outside bitbybit Studio and is not a verified bitbybit finding.
- Approximately 25 million records
- A figure referenced by a threat actor and repeated in subsequent third-party reports. bitbybit Studio does not adopt it as a verified scope unless and until it is independently established.
- A 14 GB dataset
- A dataset size quoted in external listings and reports. It did not originate from bitbybit Studio and is not a bitbybit measurement.
- A zero-day vulnerability as the cause
- Third-party reports have described a zero-day vulnerability and various possible attack paths. These are external characterisations, not bitbybit Studio’s root-cause determination.
- The described data categories
- External reports characterise the material as customer records and AI chat logs. bitbybit Studio has not confirmed that any customer information was affected, and does not adopt those categories.
- The identifier DATABASE-2026-bitbybit-studio-25M
- An external label applied by third parties. It is not a bitbybit Studio reference and carries no bitbybit-verified meaning.
Questions and answers
- Was bitbybit Studio breached?
- On 25 August 2026, bitbybit Studio became aware of a security breach affecting one of its third-party analytics vendors, and initiated its incident-response process. As published on the bitbybit status page, bitbybit has not confirmed that any bitbybit systems or customer information were affected, and any potential impact identified in the initial review would be limited to messaging services. The self-hosted third-party analytics component identified during the review was removed from the bitbybit environment, and bitbybit published that remediation was complete on 30 August 2026.
- Were 25 million bitbybit Studio records stolen?
- A threat actor and subsequent third-party reports have referenced approximately 25 million records. bitbybit Studio does not adopt that figure as a verified scope unless and until it is independently established. bitbybit has not confirmed that any customer information was affected.
- What is DATABASE-2026-bitbybit-studio-25M?
- DATABASE-2026-bitbybit-studio-25M is an identifier used by third parties in connection with claims about data allegedly associated with bitbybit Studio. The identifier, the dataset size attached to it, and the related technical claims originated outside bitbybit Studio and are not verified bitbybit findings.
- Was a zero-day vulnerability responsible?
- Third-party reports have described a zero-day vulnerability and various possible attack paths. Those descriptions are not bitbybit Studio’s root-cause determination. The component identified during bitbybit’s own review was a self-hosted third-party analytics component, which was removed from the bitbybit environment, with remediation published as complete on 30 August 2026.
- Was customer or conversation data affected?
- bitbybit Studio has not confirmed that any bitbybit systems or customer information were affected. Based on the initial review published on the bitbybit status page, any potential impact would be limited to messaging services, and services remained operational throughout. Customers with questions about their own account or deployment can contact [email protected].
- Where can I find official bitbybit Studio security updates?
- Operational updates are published on the public status page at status.bitbybit.studio. Standing first-party security information is published on the bitbybit Studio Security & Trust page, where this notice is listed.
How bitbybit handles security
Security at bitbybit is treated as an ongoing programme rather than a fixed checklist, covering application development, infrastructure, access management, third-party services, and operational process. The practices below are the standing ones, described in full on theSecurity & Trust page and governed by thePrivacy Policy.
- Encryption in transit and at rest
- Personal information is encrypted both in transit and at rest, as described in the Data Security section of the Privacy Policy.
- Controlled access
- Access to systems and to customer information requires authentication and is controlled. Inside the product, workspace roles determine what each member of your team can see and do.
- Reviewable agent activity
- AI Studio keeps logs of what your agent said and did, so agent activity can be reviewed after the fact rather than taken on trust.
- Your data stays exportable
- Customer records, conversation history, and tags remain yours, and bitbybit supports full data export — so you can take your customer database with you.
- Third-party providers are in scope
- bitbybit runs on services operated by other companies. Those providers are treated as part of the security surface rather than outside it.
- A published disclosure route
- Security researchers have a responsible disclosure process and a machine-readable contact at /.well-known/security.txt.
Where to find more
- Security & Trust — data handling, access management, third-party services, responsible disclosure, and service availability.
- Service status — current service state and operational updates.
- Privacy Policy — what information bitbybit collects and processes, why, how it is shared, and the rights available to you.
Customers with questions about their own account or deployment can reach the team at [email protected]. Security researchers should follow the responsible disclosure process rather than reporting through public channels.