AI Meeting Recorder Leaks 181K Recordings in Firestore Breach
AI News

AI Meeting Recorder Leaks 181K Recordings in Firestore Breach

4 min
8/10/2026
tl;dvdata breachFirestoreAI meeting recorder

Critical Flaw in AI Meeting Recorder Exposes 181,000 Recordings

A serious security vulnerability in tl;dv, a popular AI meeting recording platform, has exposed over 181,000 meeting recordings from more than 84,000 users. The flaw, discovered by security researcher BobDaHacker, allowed any authenticated user to access the entire Firestore database, including live conference IDs for ongoing meetings.

The exposed data spans 35,000 email domains, including government agencies from 23 countries, major universities, and corporations like HubSpot and Mitsui. The vulnerability remained unfixed for at least six months after responsible disclosure, raising serious questions about the company's security practices.

How the Vulnerability Worked

The attack exploited a missing tenant isolation in tl;dv's Firebase Firestore database. When a user authenticates with tl;dv, they receive a Firebase token that grants access to the meetings collection. This collection lacked proper security rules, allowing any authenticated user to query every meeting record across all accounts.

Each meeting record contained sensitive metadata: the creator's email address, conference ID (a joinable Google Meet or Teams room), provider, recording status, and timestamps. For meetings with a recording status, the conference ID was a live, active call, enabling an attacker to join meetings uninvited.

Real-World Impact: Joining Live Meetings

BobDaHacker demonstrated the severity by joining two live meetings. The first was a Malaysian Ministry of Education session with 157 participants. The second was a university startup team's meeting where students shared screens and discussed their project. These real-world examples show the immediate risk of unauthorized access to confidential discussions.

At any given time, roughly 1,000 meetings had a recording status, meaning there were a thousand live calls with exposed conference IDs. An attacker could potentially join all of them simultaneously using automated bots.

Scale of the Data Exposure

The researcher scraped 27,334 meeting IDs and found over 1,000 public meetings, exposing 715 invitee emails across 228 domains. This included a Brazilian government conservation meeting with participants from WWF and The Nature Conservancy, and meetings from Ukraine's Ministry of Digital Transformation.

The data also revealed usage patterns: peak month was July 2025 with 43,209 meetings, and the busiest time was Wednesday at 2pm UTC. This level of detail could be used for social engineering or corporate espionage.

continue reading below...

Disclosure Timeline and Company Response

BobDaHacker reported the vulnerability on January 28, 2026, to Raphael Allstadt, a company contact, who acknowledged it and promised the CTO would follow up. However, the CTO never responded. Despite multiple follow-ups in February, March, and July, the vulnerability remained unpatched and the company went silent.

The company's security page boasts SOC2, GDPR, and EU AI Act compliance, along with AES-256 encryption. Yet, its security response failed to meet even basic standards, contradicting its public commitment to respond within 24 hours.

Additional Flaw: Unsecured Internal App

While exploring tl;dv's subdomains, the researcher found a FIFA World Cup 2026 prediction game called "World Cup Pick'em" at worldcup.tldv.io. This internal app had zero authentication, exposing 43 player records, including 19 employees with full names and corporate emails.

The irony was not lost: a company that records millions of people's meetings had built an internal app that leaked its own employee directory. This secondary flaw highlights a systemic lack of security awareness.

Why This Matters

This incident underscores the critical importance of tenant isolation in multi-tenant databases. A single misconfigured Firestore collection can expose years of sensitive data, including job interviews, sales negotiations, and government briefings.

It also highlights a growing trend of AI meeting recorders facing legal and security scrutiny. Similar apps like Otter.ai are already facing class-action lawsuits over consent issues. This breach adds to the growing pressure on the industry to prioritize security and privacy.

What tl;dv Must Do Now

The company needs to immediately fix the Firestore security rules to enforce tenant isolation. It should also take the World Cup app offline or add authentication. Most importantly, it must respond to security researchers and communicate transparently with affected users.

As the researcher noted, "Firestore security rules exist for this." The failure to apply them to the meetings collection is a basic oversight with severe consequences. The company's silence is unacceptable, and affected users deserve answers.

This incident serves as a cautionary tale for any company handling sensitive user data. Security is not a badge to display but a practice to implement consistently.