AI Meeting Bot Tl;dv Left Government and Corporate Calls Wide Open

A security researcher found a misconfigured database in the popular meeting-recording app tl;dv that let anyone see live government and corporate video calls, and, in most cases, join them uninvited.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial shot of a rack of white networking access points and small gateway boxes mounted on a modern office ceiling, soft cool blue LEDs glowin
Share

Key points

  • A researcher known as BobDaHacker discovered in late January 2025 that any tl;dv account holder could access the app's central database and view every live meeting the app was attending worldwide.
  • More than 180,000 completed call records belonging to over 80,000 users were exposed, including meetings from government agencies in 23 countries.
  • A separate sample of 27,000-plus meeting IDs showed that more than 1,000 had participant email addresses and full transcripts sitting on the open internet.
  • BobDaHacker says they were admitted into private meetings roughly 80% of the time after posing as an AI notetaker bot.
  • The flaw remained unpatched at publication time; tl;dv did not respond to requests for comment from Dark Reading or Threat Vectr.

Tl;dv (short for "Too Long; Didn't View") is a meeting assistant that automatically joins your video calls, records them, and produces a written transcript. More than two million people use it, according to the company's own website, including staff at Salesforce, Cloudflare, dozens of government agencies, major universities, and large corporations.

In late January 2025, an application security researcher who goes by BobDaHacker discovered that the app had left a critical door unlocked.

How did the researcher get in?

The problem sits in tl;dv's back-end database, which runs on Google Firebase, a cloud platform companies use to store and manage app data. When you log into tl;dv, the app gives you a session ID, a kind of digital key card. That key card grants more access than it should.

Firebase includes a feature called Firestore, a database service. Normally, security rules (a short list of instructions the developer writes) ensure each user can only see their own data. Tl;dv applied those rules almost everywhere. Almost.

One section called the "meetings collection" had no such rules. Anyone holding a valid tl;dv session ID could query that section and pull back a list of every live meeting the app was currently attending, anywhere on earth, along with the meeting host's email address and basic details like when the call started.

"Firestore security rules are the first thing Google tells you to configure," BobDaHacker told Dark Reading, which first reported the story. "The documentation walks you through it with examples. The default rules even warn you that they're open and need to be locked down."

Could someone actually join those meetings?

Yes. Seeing a meeting's details is not the same as getting inside it, but BobDaHacker found that the gap was easy to cross.

Some meetings, including a large Google Meet call run by the Malaysian Ministry of Education's primary management training institute, were set to public and required no extra effort. For private calls, the researcher posed as an AI notetaker bot and requested entry. Hosts admitted them roughly 80% of the time. In one case, 157 participants watched the tl;dv bot appear in the participant list, and nobody raised a question.

What was exposed Scale
Completed call records More than 180,000
Affected user accounts More than 80,000
Government countries represented 23
Meeting IDs sampled for public data 27,000-plus
IDs with transcripts or emails publicly accessible More than 1,000
Meetings the researcher could join uninvited ~80% of private calls tested

Who was affected?

The exposed records included meetings from government agencies across 23 countries, identified by their ".gov" web domains. Named organisations in BobDaHacker's findings include HubSpot, Japanese real estate giant Mitsui Fudosan, Ukraine's Ministry of Digital Transformation, the state government of São Paulo in Brazil, the University of California at Berkeley, and the University of Tokyo.

For the roughly 1,000 meetings that had public sharing switched on, full transcripts and invitee email addresses were sitting on the open internet, accessible to anyone who knew where to look.

One more leak: employee personal emails from a football game

While digging through tl;dv's subdomains (the different web addresses a company uses for internal tools), BobDaHacker found an internal World Cup bracket competition called "Too Long; Didn't Score." Its player data was completely unprotected: no password, no login required. A basic web request returned the names and email addresses of all 42 tl;dv employees who had signed up. Nearly half used personal email addresses, leaking information they almost certainly never intended to make public. The game was still live weeks after the World Cup ended.

What should affected users do?

If your organisation uses tl;dv, take four practical steps now.

First, check which meetings your account has recorded and review their sharing settings. Set all sensitive recordings to private if they are not already.

Second, look at your calendar permissions. Tl;dv, like most notetaking apps, connects to your calendar to know when to join calls. Audit which third-party apps have that access and remove any you no longer need.

Third, pay attention to who is in the room. If an AI bot appears in a meeting you did not invite it to, treat that as a warning sign and remove it before discussing anything sensitive.

Finally, treat meeting transcripts like written records. If you would not email the contents of a call to a stranger, do not leave the recording set to public.

© 2026 Threat Vectr