We have identified the cause of this incident and are actively responding. Our evidence indicates the affected accounts were accessed using passwords captured on a fraudulent copy of the Pantheon login page, reached through sponsored search results and not through any compromise of Pantheon's own systems
We are securing the affected accounts, resetting credentials, and revoking access created by the unauthorized party. As part of this, you will receive a routine password-reset email.
We are also contacting affected account holders and site owners directly; those security notifications will come from helpdesk@pantheon.io and are genuine.
Posted Sep 12, 2026 - 15:51 PDT
Update
We are correcting our initial assessment. Our earlier update said the affected accounts were accessed with passwords stolen in third-party data breaches. Our evidence indicates that credentials were captured on a fraudulent copy of the Pantheon sign-in page. The look-alike page was promoted through paid search results and links, and it forwarded users to the real Pantheon Dashboard after capturing what they typed, so many affected users saw nothing unusual. We have identified and reported one such site. Sites of this kind are usually replaced quickly. We are continuing to search for others and to work with the providers involved. Pantheon's systems were not breached. Once inside an account, the unauthorized party used normal account functions: creating machine tokens, adding SSH keys, and on some affected sites, deploying code to production. We will be contacting affected account holders and site owners directly once we confirm the list of affected accounts, resetting credentials, and revoking tokens and keys on those accounts. If you are not contacted, we have no indication your account was accessed.
How to protect your account Sign in only by typing https://dashboard.pantheon.io into your browser or using a bookmark you created. Do not sign in from a search result, a sponsored ad, or a link in an email or chat message, even one that appears to come from Pantheon. Before you type a password, check that the address bar shows dashboard.pantheon.io spelled exactly; look-alike pages differ by a letter or two. Turn on multi-factor authentication for your Pantheon account (Personal Settings, then Security). Instructions: https://docs.pantheon.io/release-notes/2026/04/mfa If you have signed in from a search result or emailed link recently, change your password now, then review your account: remove SSH keys you do not recognize (https://docs.pantheon.io/ssh-keys), revoke machine tokens you did not create (https://docs.pantheon.io/machine-tokens), and check your site and workspace team lists for members you did not add. Pantheon will never ask for your password by email, chat, or phone. Report suspicious sign-in pages or messages to abuse@pantheon.io. Our security practices and contacts are published at https://pantheon.io/security and https://trust.pantheon.io.
Posted Sep 12, 2026 - 09:58 PDT
Update
Our team is still investigating the issue. The next update will be in 6 hours or when a new major update comes.
Posted Sep 12, 2026 - 03:18 PDT
Update
We are continuing to investigate this issue.
Posted Sep 11, 2026 - 21:16 PDT
Investigating
We are currently investigating reports of unauthorized access to a small number of Pantheon customer accounts. Our evidence suggests these accounts were accessed using credentials stolen from external third-party data breaches (unrelated to Pantheon). This technique, known as "credential stuffing," relies on reused passwords.
Posted Sep 11, 2026 - 21:13 PDT
This incident affects: Customer Sites, Dashboard, Global CDN, Spinup Operations, Workflow Operations, Support Tickets, Terminus Operations, Site Certificate Provisioning, Billing Operations, Autopilot, Git, Front-End Sites (Beta), and Content Publisher (Public Preview).