{
  "meta": {
    "version": "v1",
    "pricing": {
      "public": {
        "label": "Public",
        "description": "Read-only API access for lightweight status checks and public integrations."
      },
      "premium": {
        "label": "Premium",
        "description": "API keys with higher hourly quotas, plus Slack, Teams, Discord, webhook, and email outage alerts across your vendor stack."
      }
    },
    "generatedAt": "2026-08-13T04:09:30.656Z"
  },
  "data": {
    "id": "incident_statuspage_pantheon_8bdx6wxwx0cl",
    "slug": "pantheon-security-advisory-unauthorized-access-via-credential-stuffing-2026-04-15",
    "title": "Security Advisory: Unauthorized Access via Credential Stuffing",
    "summary": "Security Advisory: Unauthorized Access via Credential Stuffing",
    "status": "resolved",
    "severity": "minor",
    "startedAt": "2026-04-15T14:27:54+00:00",
    "updatedAt": "2026-04-16T20:30:54.014+00:00",
    "resolvedAt": "2026-04-16T20:30:53.991+00:00",
    "provider": {
      "slug": "pantheon",
      "name": "Pantheon"
    },
    "affectedServices": [],
    "links": {
      "html": "/incidents/pantheon-security-advisory-unauthorized-access-via-credential-stuffing-2026-04-15",
      "api": "/api/v1/incidents/pantheon-security-advisory-unauthorized-access-via-credential-stuffing-2026-04-15",
      "providerHtml": "/providers/pantheon",
      "alerts": "https://outagedeck.com/account?stack=pantheon&utm_source=api&utm_medium=response&utm_campaign=api_alerts&utm_content=incident"
    },
    "impactSummary": "Pantheon reported a none event for the affected tracked services.",
    "source": {
      "id": "source_pantheon_status",
      "kind": "official_api",
      "name": "Pantheon Operations Status",
      "checkedAt": "2026-08-13T04:00:29.141+00:00",
      "officialUrl": "https://status.pantheon.io",
      "statusPageUrl": "https://status.pantheon.io"
    },
    "updates": [
      {
        "id": "update_statuspage_pantheon_8bdx6wxwx0cl_g15r633gft0g",
        "status": "investigating",
        "body": "We are currently investigating reports of unauthorized access to a small number of Pantheon customer accounts.\nOur evidence suggests these accounts were accessed using credentials stolen from external third-party data breaches (unrelated to Pantheon). This technique, known as \"credential stuffing,\" relies on reused passwords.\n\nRequired Actions for All Customers\n• Audit Your Sites: Check for unexpected code or file modifications. If you find any suspicious changes, contact Pantheon Support immediately.\n• Enable MFA (High Priority): Multi-factor authentication is your best defense against password theft.\n• Enable MFA here: https://docs.pantheon.io/guides/account-mgmt/account/mfa\n• Update Your Password: If you use your Pantheon password on any other site, change it immediately to a unique, strong passphrase.\nNext Steps: We are continuing our investigation and will provide further updates as more information becomes available.",
        "createdAt": "2026-04-15T14:27:54.973+00:00"
      },
      {
        "id": "update_statuspage_pantheon_8bdx6wxwx0cl_j1r6mfsjtv3c",
        "status": "resolved",
        "body": "Final Update: We have concluded our investigation into the reports of unauthorized account access. Our team has worked directly with the small number of affected customers to secure their accounts and remediate any unauthorized changes.\n\nMonitoring & Conclusion: We have seen no further evidence of unauthorized activity related to this incident. Our systems remain secure, and we continue to monitor for suspicious login patterns.\n\nOngoing Security Best Practices: While this incident is resolved, credential stuffing remains a common web-wide threat. To keep your account secure, we strongly recommend:\n\n• Enabling MFA on all Pantheon user accounts.\n• Using unique passwords managed via a password manager.\n• Rotating secrets/keys if you suspect your local environment has been compromised.\n\nThank you for your patience as we worked to keep the Pantheon community secure.",
        "createdAt": "2026-04-16T20:30:53.991+00:00"
      }
    ],
    "access": {
      "plan": "public",
      "keyed": false
    }
  }
}