Protecting Your Pantheon Account and Sites from Look-Alike Login Attacks

| 3 min read

We recently discovered a bad actor who created a Pantheon lookalike login page and funnelled unsuspecting traffic there by purchasing paid Google ads for keywords like “pantheon login.” The bad actor then used stolen credentials to access targeted accounts, in some cases reaching customer sites.

Pantheon’s systems were never compromised, but we want to explain what happened, what it means for Pantheon customers, and the practical steps you can take to protect your account and site in a threat environment that increasingly includes site spoofing as an attack vector.

We have completed mitigation steps for the compromised accounts, including resetting passwords and revoking unauthorized machine tokens and SSH keys. We are continuing to notify affected account holders and site owners directly, with specific guidance based on what we observed.

How the attack worked

The cyberattack relied on a familiar but effective technique: making a fraudulent login experience look trustworthy enough that someone enters their credentials.

At a high level:

  • A person searched Google for “Pantheon login” and followed a link from a sponsored ad.
  • The result led to a fraudulent page designed to resemble a Pantheon sign-in experience.
  • The page captured the credentials and forwarded the person to the real Pantheon dashboard, making the interaction appear normal.
  • The unauthorized party later used the captured credentials to sign in.
  • Where additional access was created, a password reset alone was not enough to remove it. Machine tokens, sessions, and SSH keys also had to be revoked.

You should always navigate directly to the real Pantheon dashboard (dashboard.pantheon.io)  and enable multi-factor authentication. A look-alike page can be very convincing, but it cannot bypass a strong second factor when that factor is required at sign-in.

What Pantheon has done

Our response has focused on containing account access, protecting customer sites, and improving detection:

  • Resetting passwords for compromised accounts.
  • Revoking unauthorized machine tokens and SSH keys.
  • Terminating unauthorized access created through affected accounts.
  • Reviewing the sites those accounts could reach.
  • Contacting affected account holders and site owners directly.
  • Adding detection and response measures for this pattern of activity.
  • Contacted the advertising provider
  • Contacted the domain provider of the spoofed domain

What you can do to protect your account immediately

1. Use multi-factor authentication or enable your organization’s single sign-on portal

Turn on MFA for your Pantheon account, or enable your organization’s single sign-on (SSO) portal, especially for site owners, administrators, and anyone who can create tokens or manage deployment access. MFA and SSO are among the strongest protections against a stolen password being used successfully.

2. Sign in directly

Always navigate directly to dashboard.pantheon.io or use a bookmark you created yourself. Do not sign in through a sponsored search result, an unexpected email link, or a look-alike domain.

Before entering credentials, check the address bar carefully. A page can copy Pantheon’s logo, colors, and wording while still being controlled by someone else.

3. Use a unique password

Use a long, unique password for Pantheon. Never reuse it on another service. If you entered your Pantheon password into a suspicious page, change it immediately anywhere else that password was used.

4. Review account access

Review your account’s team members, machine tokens, and SSH keys. Remove anything you do not recognize. If your account was identified as affected, follow the instructions in Pantheon’s direct notification and reissue any keys or tokens your team or build pipeline still needs.

Account security and site security are connected. If an account with access to a site is compromised, review the site as well as the account.

  • Review recent commits and deployments for changes nobody on your team recognizes.
  • Review administrator accounts and remove accounts that should not be present.
  • Review installed plugins, themes, and must-use plugins, and remove anything unauthorized.
  • Check configuration files and uploads for unexpected changes.
  • Rotate site-team credentials, SSH keys, and machine tokens when appropriate.
  • Keep SFTP mode off when you are not actively using it, and use version-controlled deployment workflows where possible.
  • If you find something suspicious, preserve the evidence and contact Pantheon Support before making broad cleanup changes. Removing one visible file may not remove persistence elsewhere in a site.

Customers who are directly affected will receive more specific, site-level instructions. Do not assume that a site is clean based only on a password reset or a restored file; the right review depends on what access was observed.

Pantheon’s security commitment

Security is a shared responsibility, but the burden should not fall entirely on customers. Pantheon is continuing to improve the controls that protect account access, detect unusual activity, and limit what a compromised credential can do.

AI makes it easier to produce polished copy, convincing page layouts, and realistic brand impersonation at scale. That does not change the fundamentals of account protection: verify the domain, use MFA, and avoid entering credentials after arriving through an untrusted link.

Treat unexpected urgency, unfamiliar login domains, and sponsored results that look slightly different from the destination you expect as warning signs. When in doubt, close the page and navigate to the service directly.

We will continue to notify affected customers directly and provide updates as our review progresses. If you have questions or notice unexpected activity, contact Pantheon Support through the normal support channel.

Author

Joey Stanford

Discover More

Why we’re deploying a new PHP runtime

6 min read
Read More

Pantheon Joins Drupal AI Initiative

3 min read
Read More

From ChatGPT to AI Overviews: How Enterprises Win in Multiplatform AI Search

5 min read
Read More
Request a Pantheon platform demo