Live  /  Incidents  /  Pantheon Operations

Pantheon Operations: Security Advisory: Malicious Activity Affecting Platform Hosts

Pantheon Operations · pantheon.ioImpact: nonemonitoring2026-10-02 15:05 UTC
Public — what happened

Summary

As our investigation has continued, we have determined that a small number of customer sites — not one — were affected. In each case, the site was first compromised through a weakness in its own application, then used to interact with platform services. We are working directly with the affected customers on cleanup and credential rotation, and we have added platform controls to restrict this activity and detection to identify it going forward. The activity remains limited to the individual affected sites and their own data. We have found no evidence that any other customer's site or data was accessed. What you can do: Keeping your site current is the most effective protection. Please up

Timeline

Source of record: provider status page. Mirrored as reported; times in UTC.

Independent path health

The status page is the symptom. SquidGrid measures the paths that reach Pantheon Operations against their own baselines — whether the routes carrying your traffic degraded, at which handoff, and who owns that stretch.

🔒 Sign in to see
Customers get the live Provider Assessment Report for Pantheon Operations: its full incident track record, what tends to break, and recent public reports of problems.

Included with any paid plan.

Open the Pantheon Operations report →

Related: Pantheon Operations status & history. SquidGrid is not affiliated with Pantheon Operations.