Live  /  Incidents  /  Pantheon Operations

Pantheon Operations: Security Advisory: Unauthorized Access to Customer Accounts via a Look-alike Sign-in Page

Pantheon Operations · pantheon.ioImpact: minorResolved2026-09-15 01:01 UTC
Public — what happened

Summary

We have completed mitigation for this incident. All confirmed affected accounts have had passwords reset and unauthorized access, machine tokens, and SSH keys revoked. All confirmed affected account holders and site owners have been contacted directly. We will continue monitoring the situation and share an update if anything changes.

Timeline

Source of record: provider status page. Mirrored as reported; times in UTC.

Independent path health

The status page is the symptom. SquidGrid measures the paths that reach Pantheon Operations against their own baselines — whether the routes carrying your traffic degraded, at which handoff, and who owns that stretch.

🔒 Sign in to see
Customers get the live Provider Assessment Report for Pantheon Operations: its full incident track record, what tends to break, and recent public reports of problems.

Included with any paid plan.

Open the Pantheon Operations report →

Related: Pantheon Operations status & history. SquidGrid is not affiliated with Pantheon Operations.