Security Advisory: Unauthorized Access to Customer Accounts via a Look-alike Sign-in Page

Incident Report for Pantheon Operations

Monitoring

We have completed mitigation steps for the compromised accounts, including resetting passwords and revoking unauthorized access, machine tokens, and SSH keys.

We are continuing to notify affected account holders and site owners directly. Customers who are affected will receive specific guidance from Pantheon through our support channels.

Pantheon’s systems were not compromised. We will continue monitoring the situation and provide further updates as our review progresses.
Posted Sep 13, 2026 - 09:26 PDT

Identified

We have identified the cause of this incident and are actively responding. Our evidence indicates the affected accounts were accessed using passwords captured on a fraudulent copy of the Pantheon login page, reached through sponsored search results and not through any compromise of Pantheon's own systems

We are securing the affected accounts, resetting credentials, and revoking access created by the unauthorized party. As part of this, you will receive a routine password-reset email.

We are also contacting affected account holders and site owners directly; those security notifications will come from helpdesk@pantheon.io and are genuine.
Posted Sep 12, 2026 - 15:51 PDT

Update

We are correcting our initial assessment. Our earlier update said the affected accounts were accessed with passwords stolen in third-party data breaches. Our evidence indicates that credentials were captured on a fraudulent copy of the Pantheon sign-in page. The look-alike page was promoted through paid search results and links, and it forwarded users to the real Pantheon Dashboard after capturing what they typed, so many affected users saw nothing unusual.
We have identified and reported one such site. Sites of this kind are usually replaced quickly. We are continuing to search for others and to work with the providers involved.
Pantheon's systems were not breached. Once inside an account, the unauthorized party used normal account functions: creating machine tokens, adding SSH keys, and on some affected sites, deploying code to production. We will be contacting affected account holders and site owners directly once we confirm the list of affected accounts, resetting credentials, and revoking tokens and keys on those accounts. If you are not contacted, we have no indication your account was accessed.

How to protect your account
Sign in only by typing https://dashboard.pantheon.io into your browser or using a bookmark you created. Do not sign in from a search result, a sponsored ad, or a link in an email or chat message, even one that appears to come from Pantheon. Before you type a password, check that the address bar shows dashboard.pantheon.io spelled exactly; look-alike pages differ by a letter or two.
Turn on multi-factor authentication for your Pantheon account (Personal Settings, then Security). Instructions: https://docs.pantheon.io/release-notes/2026/04/mfa
If you have signed in from a search result or emailed link recently, change your password now, then review your account: remove SSH keys you do not recognize (https://docs.pantheon.io/ssh-keys), revoke machine tokens you did not create (https://docs.pantheon.io/machine-tokens), and check your site and workspace team lists for members you did not add.
Pantheon will never ask for your password by email, chat, or phone. Report suspicious sign-in pages or messages to abuse@pantheon.io. Our security practices and contacts are published at https://pantheon.io/security and https://trust.pantheon.io.
Posted Sep 12, 2026 - 09:58 PDT

Update

Our team is still investigating the issue. The next update will be in 6 hours or when a new major update comes.
Posted Sep 12, 2026 - 03:18 PDT

Update

We are continuing to investigate this issue.
Posted Sep 11, 2026 - 21:16 PDT

Investigating

We are currently investigating reports of unauthorized access to a small number of Pantheon customer accounts.
Our evidence suggests these accounts were accessed using credentials stolen from external third-party data breaches (unrelated to Pantheon). This technique, known as "credential stuffing," relies on reused passwords.
Posted Sep 11, 2026 - 21:13 PDT
This incident affects: Customer Sites, Dashboard, Global CDN, Spinup Operations, Workflow Operations, Support Tickets, Terminus Operations, Site Certificate Provisioning, Billing Operations, Autopilot, Git, Front-End Sites (Beta), and Content Publisher (Public Preview).