Security notice - 19 July 2026
On 19 July 2026 our systems were hit by a targeted attack, carried out with a coordinated swarm of bots. We detected it, blocked it, and investigated it fully. No customer data, passwords, payment details, or servers were accessed, and no accounts were created, changed, or reset.
This page explains what happened, what you may have noticed, and what we did.
What happened
This was not random background noise. A swarm of bots, spread across a large pool of addresses on Alibaba Cloud, was directed at our public API for several hours in a deliberate attempt to get in. It tried three things:
- Injection attempts against our data endpoints, aimed at reading data it should not see.
- Enumeration, guessing account and email addresses to build a target list.
- Abuse of our sign-up and password-reset flows, firing off large numbers of "confirm your email" and "password reset" messages to addresses it had guessed.
All three failed at the parts that matter. The injection attempts did not execute (our queries are parameterised). Our credential and secret stores were never reachable from the public API. The attacker never logged in to any account.
What did NOT happen
- No customer data was read or copied.
- No passwords, payment details, or API keys were exposed.
- No servers, VMs, or backups were accessed or changed.
- No account was created, modified, or had its password reset.
We verified each of these directly against our logs and databases, not by assumption.
What you may have noticed
Two things could have reached you:
-
Unexpected emails. Some people received "Welcome, confirm your email" or "password reset" messages they never asked for. These were triggered by the attacker, not by any real action on your account. You can safely ignore and delete them. Do not click links inside emails you did not expect. Nothing was created or reset on your side.
-
You were logged out. As a precaution we rotated the keys that sign our login sessions. This ended every active session at once. If you were asked to log in again, that is why. Your password did not change, and your normal password still works.
What we did
- Blocked the Alibaba Cloud network ranges the attack came from, at both our servers and our edge.
- Rotated internal credentials and signing keys as a precaution, even though none were exposed.
- Added rate limiting to the sign-up, confirmation, and password-reset endpoints so this cannot be used to flood mailboxes again.
- Closed and hardened every path the bot probed.
- Reported the attack, together with the source IP addresses used in the swarm, to the relevant authorities in Hong Kong and Singapore, where the traffic originated.
If you normally connect to us from an Alibaba Cloud address, you may now be blocked as a side effect. Contact [email protected] and we will allow your address.
What you should do
As a precaution, we strongly recommend you change the root and administrator passwords on your servers. We have no proof that any password was exposed, but changing them costs little and removes any doubt.
Your Euronodes account (panel) password is unchanged and still works. You can also change it in the panel if you wish.
If you saw anything on your account you cannot explain, or received emails that worry you, contact us at [email protected] and we will check it with you.
We take this seriously. If you have questions, we are happy to answer them.
The Euronodes Team