Live / Incidents / Pantheon Operations
Pantheon Operations: Security Advisory: Malicious Activity Affecting Platform Hosts
Pantheon Operations · pantheon.ioImpact: nonemonitoring2026-10-02 15:05 UTC
Public — what happened
Summary
As our investigation has continued, we have determined that a small number of customer sites — not one — were affected.
In each case, the site was first compromised through a weakness in its own application, then used to interact with platform services. We are working directly with the affected customers on cleanup and credential rotation, and we have added platform controls to restrict this activity and detection to identify it going forward.
The activity remains limited to the individual affected sites and their own data. We have found no evidence that any other customer's site or data was accessed.
What you can do: Keeping your site current is the most effective protection.
Please up
Timeline
- Started — 2026-10-01 19:38 UTC
- Last update — 2026-10-02 15:05 UTC
- Ongoing at last check.
With SquidGrid — where it starts on the route
Independent path health
The status page is the symptom. SquidGrid measures the paths that reach Pantheon Operations against their own baselines — whether the routes carrying your traffic degraded, at which handoff, and who owns that stretch.
🔒 Sign in to seeCustomers get the live Provider Assessment Report for Pantheon Operations: its full incident track record, what tends to break, and recent public reports of problems.
Included with any paid plan.
Open the Pantheon Operations report →