Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Pantheon

Security Advisory: Unauthorized Access to Customer Accounts via a Look-alike Sign-in Page

Minor
September 12, 2026 - Started about 18 hours ago
Official incident page

Incident Report

We are currently investigating reports of unauthorized access to a small number of Pantheon customer accounts. Our evidence suggests these accounts were accessed using credentials stolen from external third-party data breaches (unrelated to Pantheon). This technique, known as "credential stuffing," relies on reused passwords.

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
INVESTIGATING about 6 hours ago - at 09/12/2026 04:58PM

We are correcting our initial assessment. Our earlier update said the affected accounts were accessed with passwords stolen in third-party data breaches. Our evidence indicates that credentials were captured on a fraudulent copy of the Pantheon sign-in page. The look-alike page was promoted through paid search results and links, and it forwarded users to the real Pantheon Dashboard after capturing what they typed, so many affected users saw nothing unusual.
We have identified and reported one such site. Sites of this kind are usually replaced quickly. We are continuing to search for others and to work with the providers involved.
Pantheon's systems were not breached. Once inside an account, the unauthorized party used normal account functions: creating machine tokens, adding SSH keys, and on some affected sites, deploying code to production. We will be contacting affected account holders and site owners directly once we confirm the list of affected accounts, resetting credentials, and revoking tokens and keys on those accounts. If you are not contacted, we have no indication your account was accessed.

How to protect your account
Sign in only by typing https://dashboard.pantheon.io into your browser or using a bookmark you created. Do not sign in from a search result, a sponsored ad, or a link in an email or chat message, even one that appears to come from Pantheon. Before you type a password, check that the address bar shows dashboard.pantheon.io spelled exactly; look-alike pages differ by a letter or two.
Turn on multi-factor authentication for your Pantheon account (Personal Settings, then Security). Instructions: https://docs.pantheon.io/release-notes/2026/04/mfa
If you have signed in from a search result or emailed link recently, change your password now, then review your account: remove SSH keys you do not recognize (https://docs.pantheon.io/ssh-keys), revoke machine tokens you did not create (https://docs.pantheon.io/machine-tokens), and check your site and workspace team lists for members you did not add.
Pantheon will never ask for your password by email, chat, or phone. Report suspicious sign-in pages or messages to abuse@pantheon.io. Our security practices and contacts are published at https://pantheon.io/security and https://trust.pantheon.io.

INVESTIGATING about 12 hours ago - at 09/12/2026 10:18AM

Our team is still investigating the issue. The next update will be in 6 hours or when a new major update comes.

INVESTIGATING about 18 hours ago - at 09/12/2026 04:16AM

We are continuing to investigate this issue.

INVESTIGATING about 18 hours ago - at 09/12/2026 04:13AM

We are currently investigating reports of unauthorized access to a small number of Pantheon customer accounts.
Our evidence suggests these accounts were accessed using credentials stolen from external third-party data breaches (unrelated to Pantheon). This technique, known as "credential stuffing," relies on reused passwords.

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook