We have identified the cause of this incident and are actively responding. Our evidence indicates the affected accounts were accessed using passwords captured on a fraudulent copy of the Pantheon login page, reached through sponsored search results and not through any compromise of Pantheon's own systems We are securing the affected accounts, resetting credentials, and revoking access created by the unauthorized party. As part of this, you will receive a routine password-reset email. We are also contacting affected account holders and site owners directly; those security notifications will come from helpdesk@pantheon.io and are genuine.
Monitors
Security Advisory: Unauthorized Access to Customer Accounts via a Look-alike Sign-in Page
Pantheon