Melbourne-based ticket resale platform Tixel notified users of a cybersecurity incident resulting from a zero-day SQL injection vulnerability (CVE-2026-72898) in its third-party analytics vendor, Metabase. The vulnerability permitted unauthorized access to a Metabase application database, exposing customer email addresses and mobile phone numbers. Tixel confirmed that core internal infrastructure, accounts, passwords, payment processing details, credit card numbers, and ticket transaction histories remained uncompromised. Tixel rotated connection API keys, revoked unauthorized connections, patched the software instance, and issued customer warnings regarding potential phishing and scam campaigns.