Live / Incidents / Pantheon Operations
Pantheon Operations: Security Advisory: Unauthorized Access to Customer Accounts via a Look-alike Sign-in Page
Pantheon Operations · pantheon.ioImpact: minorResolved2026-09-15 01:01 UTC
Public — what happened
Summary
We have completed mitigation for this incident. All confirmed affected accounts have had passwords reset and unauthorized access, machine tokens, and SSH keys revoked. All confirmed affected account holders and site owners have been contacted directly.
We will continue monitoring the situation and share an update if anything changes.
Timeline
- Started — 2026-09-12 04:13 UTC
- Last update — 2026-09-15 01:01 UTC
- Resolved — 2026-09-15 20:09 UTC
With SquidGrid — where it starts on the route
Independent path health
The status page is the symptom. SquidGrid measures the paths that reach Pantheon Operations against their own baselines — whether the routes carrying your traffic degraded, at which handoff, and who owns that stretch.
🔒 Sign in to seeCustomers get the live Provider Assessment Report for Pantheon Operations: its full incident track record, what tends to break, and recent public reports of problems.
Included with any paid plan.
Open the Pantheon Operations report →