If you received an email sent by Compilatio on July 17, 2026, with the subject line “Action Required - Reset Your Password Due to Suspected Malicious Activity", this means that one or more attempts to access your user account have been detected.
Description of the Incident
Compilatio services are protected by numerous security measures designed to ensure the confidentiality of your data and access to your account, including protection against “brute force” login attempts. This technique involves making a large number of login attempts until the password is discovered.
However, on July 13, 2026, we discovered that user accounts had been subjected to “brute-force” login attempts.
In many cases, these instances of unauthorized access to the account were followed by the following actions:
- Changing the interface language to Spanish
- Deleting the User's Old Documents
- Uploading one or more documents
- Document Analysis
- Download Analysis Reports
- Deleting Analyzed Documents
This suggests that the person (or persons) who accessed your account was (were) attempting to use Compilatio's services without paying the applicable fees.
Impact on Affected Users
If a third party has accessed your account, they may have:
- View, edit, and delete certain data (personal information, password, uploaded documents, analysis reports)
- Using the software: Uploading documents and running analyses
What should I do if this applies to me?
The first step is to restore secure access to your user account.
To do this, use the link Forgot your password? from the Compilatio login page.
You must set a new "strong" and "unique" password.
Strong, so that it isn't easy to guess, and unique, so that your password doesn't appear on a list of commonly used passwords.
Once you've logged in to your account, please check to see if any changes have been made to your information.
To do this, go to the user menu, under the section My settings, tab My activity. You can view a list of the most recent actions performed on your account. Please verify that the actions listed are ones you performed yourself.
If you notice any harmful actions that you did not perform yourself, please contact support (support@compilatio.net) by sharing the list of these actions.
Tracking the Incident and Its Resolution
- Date a suspected case was reported: July 10, 2026
- Date the vulnerability was identified: July 13, 2026
- Date of identification of the affected accounts: July 17, 2026
- Date of the earliest observed case: March 2025
- Resolution Date: July 18, 2026
Corrective actions taken:
- July 13, 2026:
- Strengthening the system to protect against brute-force login attempts
- July 17, 2026:
- Identify user accounts that have had more than 100 failed login attempts in a single day, followed by a successful login
- Reset the passwords for the affected accounts and send an informational email to the user account explaining the password reset process, including instructions for creating a strong password
- Reporting the Incident to the CNIL
- July 18, 2026:
- Implementation of a system to temporarily block an IP address following an excessive number of invalid requests
Upcoming Actions
- Notice to the directors and data controllers of the relevant institutions
- Support from an expert in system and application penetration testing: conducting a black-box test followed by a gray-box test. Scheduling a test once a year
- Setting Up Two-Factor Authentication
- When creating a new password, verify that it is not included in any lists of leaked passwords