Service notice
We're responding to a security incident.
On 24 July 2026 an unauthorised party gained control of DNS for cubepilot.org for part of one day and used it to intercept traffic to our internal business systems. We have taken our cubepilot.org services offline while we verify them. Email on cubepilot.com is unaffected and remains the way to reach us. This page is where we will post updates.
Current state
What we're asking you to do
Change your password if you reused it
The certificates obtained by the attacker covered every cubepilot.org subdomain, so credentials entered on any of our services on 24 July may have been captured — the portal and the forum included. If you used the same password anywhere else, change it there now.
Hold off flashing firmware downloaded on 24–25 July
We are verifying checksums on every published image. Until we confirm them here, do not flash anything downloaded during that window. Images you obtained before 24 July are unaffected.
Treat requests for your credentials as hostile
CubePilot will never ask for your password, a verification code, or payment details by email or message. Forward anything that does to admins@cubepilot.com.
Check invoice and payment details by phone
If you receive changed bank details or a payment request that appears to come from us, confirm it with your usual contact by phone before acting on it.
What we've done
We regained control of our domains and restored our own nameservers on 24 July, took the affected systems offline, and had the fraudulently issued certificates revoked. We have preserved the evidence, reported the incident to the Australian Cyber Security Centre, and referred it for law enforcement investigation. External providers involved have been notified.
We are working through what data was reachable during the period of unauthorised access. Where personal information was involved, we will contact the people affected directly and meet our obligations under the Privacy Act. We would rather tell you something confirmed late than something wrong early.