Update - Jul 20, 2026 - 18:15 UTC
What we've fixed
Following our initial communication, we have implemented a number of additional security enhancements:
1. Credential protection audit. We reviewed how credentials are stored across our systems and implemented additional encryption for credential data where enhanced protection was identified as appropriate.
2. Implemented additional browser-side protections to address an identified browser-related exposure scenario. Stored credentials are no longer sent back to the browser when the integrations screen is opened. This, combined with the storage enhancement above, significantly reduces potential exposure risks associated with credential handling.
3. Completed a full logging audit. We reviewed our logging systems end-to-end and updated our logging configuration to prevent credential values from being recorded in application logs.
4. Cleaning up stale data. We deleted old ESP connections that had been kept after they stopped being used, and we're in the process of removing old, unused keys still on file.
Based on our investigation to date, we have not identified any indication of impact on the Stripo Plugin. Stripo does not store customers' financial or payment information. Accordingly, based on our investigation to date, we have not identified any impact on financial or payment data maintained by Stripo. Based on the information currently available, we have not identified any impact on our primary production systems. The activity identified to date appears to have been associated with a backup environment. We've implemented additional security measures for that environment and are continuing to assess whether there is any broader impact as part of our ongoing investigation.
Compliance certifications
We maintain an independently audited security program, including SOC 2 and ISO certifications. As part of this investigation, we identified opportunities to further strengthen certain technical controls related to the handling of export credentials.
We have implemented additional safeguards addressing the matters identified during our investigation. We are also incorporating the findings from this investigation into our security program, risk assessment processes, technical controls, and future audit activities. These findings have informed additional technical safeguards and will continue to be incorporated into our security controls and audit program. Security certifications demonstrate that an organization's security program has been independently assessed against recognized standards. Like any security framework, they support continuous improvement as new risks and implementation considerations are identified.
Ongoing investigation
Our investigation remains ongoing. As part of this work, we continue to review access activity relating to the database instances where the relevant data is stored. Should we identify confirmed findings that are material to affected customers, we will communicate them without undue delay.
Jul 20, 2026 - 18:15 UTC
Investigating -
Stripo Security Incident
How this started
We received two customer reports regarding unusual activity associated with ESP accounts. While an individual report could reasonably have been attributed to a variety of causes, including configuration issues, legacy integrations, or provider-specific factors, the second report involved a different ESP provider and exhibited similar characteristics. At that point, we determined that the observed pattern warranted a comprehensive security review and initiated a broader investigation.
Current status
As we identified accounts with stored ESP credentials, we reached out asking those customers to rotate their keys as a priority. This was not a single, complete pass: as our investigation continued, we identified additional accounts that required the same notification, and we've been contacting them as they're confirmed.
If you have ESP credentials connected to Stripo and haven't rotated them yet:
1. Revoke the old key there; generating a new key doesn't automatically disable the old one.
2. Generate a new key in your ESP account.
3. Update the new key in Stripo under Project Settings → Integrations.
4. Review your ESP or CRM account's recent activity: login history, contact list changes, and any campaigns or sends you don't recognize.
One reminder while all this is underway: we will never ask you to send a key, token, or password by email or in a support chat.
Ongoing investigation
Our investigation is continuing. Should we identify any confirmed findings that are material to affected customers, we will communicate them without undue delay.
Jul 16, 2026 - 09:00 UTC