What happened?
On 18 September 2026, our routine internal security checks, identified unauthorized access to a storage bucket. Our preliminary investigation indicates that relevant credentials were placed outside approved Exotel-managed systems without authorisation, contrary to Exotel’s internal security policies. The storage bucket contained certain CSV files pertaining to ExoCampaign, one of the products in the Exotel suite.
The unauthorised access was confined to this storage bucket. We have not identified any impact on other Exotel products or services.
What did we do?
Once the incident was identified, our Information Security team moved immediately to contain it and began an investigation. Containment measures included
- Restricting access to the affected environment
- Revoking or rotating the relevant credentials
- Strengthening relevant security controls based on the findings so far.
- Notifying impacted customers through our established incident-response and notification channels
We will share further updates as we get more information around this.
What does this mean for our customers?
There has been no identified impact on the availability or functioning of the Exotel platform, and no action is required from customers at this time.
More broadly, we believe our customers should have visibility into security events relevant to our environment. Our approach is to communicate proactively wherever we believe transparency is appropriate, not only where it is required.
Looking ahead
Our investigation to date indicates the incident was limited in scope, but we are treating it seriously, and we are using the findings to further strengthen our security posture.
Exotel’s security programme is built on layered, industry-standard controls, including round-the-clock managed threat detection and response across our endpoints and cloud infrastructure, zero-trust network access, centralised security monitoring, continuous monitoring of our external attack surface and regular employee phishing simulations. Following this incident, we have further tightened network and access controls across our cloud environment, expanded storage-access logging with real-time anomaly detection, and initiated a comprehensive review of user access.
Our commitment
Security is an ongoing responsibility, not a one-time exercise. We are grateful for the trust our customers place in Exotel every day, and we will continue to approach that responsibility with the diligence it deserves.
