Identified - We have identified the cause of this incident and are actively responding. Our evidence indicates the affected accounts were accessed using passwords captured on a fraudulent copy of the Pantheon login page, reached through sponsored search results and not through any compromise of Pantheon's own systems
We are securing the affected accounts, resetting credentials, and revoking access created by the unauthorized party. As part of this, you will receive a routine password-reset email.
We are also contacting affected account holders and site owners directly; those security notifications will come from helpdesk@pantheon.io and are genuine.
Sep 12, 2026 - 15:51 PDT
We are securing the affected accounts, resetting credentials, and revoking access created by the unauthorized party. As part of this, you will receive a routine password-reset email.
We are also contacting affected account holders and site owners directly; those security notifications will come from helpdesk@pantheon.io and are genuine.
Sep 12, 2026 - 15:51 PDT
Update - We are correcting our initial assessment. Our earlier update said the affected accounts were accessed with passwords stolen in third-party data breaches. Our evidence indicates that credentials were captured on a fraudulent copy of the Pantheon sign-in page. The look-alike page was promoted through paid search results and links, and it forwarded users to the real Pantheon Dashboard after capturing what they typed, so many affected users saw nothing unusual.
We have identified and reported one such site. Sites of this kind are usually replaced quickly. We are continuing to search for others and to work with the providers involved.
Pantheon's systems were not breached. Once inside an account, the unauthorized party used normal account functions: creating machine tokens, adding SSH keys, and on some affected sites, deploying code to production. We will be contacting affected account holders and site owners directly once we confirm the list of affected accounts, resetting credentials, and revoking tokens and keys on those accounts. If you are not contacted, we have no indication your account was accessed.
How to protect your account
Sign in only by typing https://dashboard.pantheon.io into your browser or using a bookmark you created. Do not sign in from a search result, a sponsored ad, or a link in an email or chat message, even one that appears to come from Pantheon. Before you type a password, check that the address bar shows dashboard.pantheon.io spelled exactly; look-alike pages differ by a letter or two.
Turn on multi-factor authentication for your Pantheon account (Personal Settings, then Security). Instructions: https://docs.pantheon.io/release-notes/2026/04/mfa
If you have signed in from a search result or emailed link recently, change your password now, then review your account: remove SSH keys you do not recognize (https://docs.pantheon.io/ssh-keys), revoke machine tokens you did not create (https://docs.pantheon.io/machine-tokens), and check your site and workspace team lists for members you did not add.
Pantheon will never ask for your password by email, chat, or phone. Report suspicious sign-in pages or messages to abuse@pantheon.io. Our security practices and contacts are published at https://pantheon.io/security and https://trust.pantheon.io.
Sep 12, 2026 - 09:58 PDT
We have identified and reported one such site. Sites of this kind are usually replaced quickly. We are continuing to search for others and to work with the providers involved.
Pantheon's systems were not breached. Once inside an account, the unauthorized party used normal account functions: creating machine tokens, adding SSH keys, and on some affected sites, deploying code to production. We will be contacting affected account holders and site owners directly once we confirm the list of affected accounts, resetting credentials, and revoking tokens and keys on those accounts. If you are not contacted, we have no indication your account was accessed.
How to protect your account
Sign in only by typing https://dashboard.pantheon.io into your browser or using a bookmark you created. Do not sign in from a search result, a sponsored ad, or a link in an email or chat message, even one that appears to come from Pantheon. Before you type a password, check that the address bar shows dashboard.pantheon.io spelled exactly; look-alike pages differ by a letter or two.
Turn on multi-factor authentication for your Pantheon account (Personal Settings, then Security). Instructions: https://docs.pantheon.io/release-notes/2026/04/mfa
If you have signed in from a search result or emailed link recently, change your password now, then review your account: remove SSH keys you do not recognize (https://docs.pantheon.io/ssh-keys), revoke machine tokens you did not create (https://docs.pantheon.io/machine-tokens), and check your site and workspace team lists for members you did not add.
Pantheon will never ask for your password by email, chat, or phone. Report suspicious sign-in pages or messages to abuse@pantheon.io. Our security practices and contacts are published at https://pantheon.io/security and https://trust.pantheon.io.
Sep 12, 2026 - 09:58 PDT
Update - Our team is still investigating the issue. The next update will be in 6 hours or when a new major update comes.
Sep 12, 2026 - 03:18 PDT
Sep 12, 2026 - 03:18 PDT
Update - We are continuing to investigate this issue.
Sep 11, 2026 - 21:16 PDT
Sep 11, 2026 - 21:16 PDT
Investigating - We are currently investigating reports of unauthorized access to a small number of Pantheon customer accounts.
Our evidence suggests these accounts were accessed using credentials stolen from external third-party data breaches (unrelated to Pantheon). This technique, known as "credential stuffing," relies on reused passwords.
Sep 11, 2026 - 21:13 PDT
Our evidence suggests these accounts were accessed using credentials stolen from external third-party data breaches (unrelated to Pantheon). This technique, known as "credential stuffing," relies on reused passwords.
Sep 11, 2026 - 21:13 PDT
Customer Sites
Operational
Dashboard
Degraded Performance
Global CDN
Operational
Spinup Operations
Operational
Workflow Operations
Operational
Support Tickets
Operational
Support Chat
Operational
Terminus Operations
Operational
Site Certificate Provisioning
Operational
Billing Operations
Operational
Autopilot
Operational
Git
Operational
Front-End Sites (Beta)
Operational
Content Publisher (Public Preview)
Operational
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance