In short

On 29 July 2026, for a period of under four hours, our website displayed a counterfeit page that asked visitors to run a command on their own computer. We removed it the same day.

Action is only needed if you actually copied and ran that command. If you did not — which will be the case for almost everyone who reads this — there is nothing for you to do. Simply having seen the page carries no risk.

We are publishing this notice because visitors are not identifiable to us, so we cannot contact the people concerned directly.


Our product and your account data were not affected

This incident concerned libertify.com, our public marketing website, and nothing else.

Our application runs on entirely separate infrastructure: its own servers, its own databases, its own credentials and its own access controls. It shares no hosting account, no administrative login and no database with the website. The compromise was contained to the website’s hosting environment throughout, and our application was not involved at any point.

Concretely, this means:

  • No customer account, no application data and no content you have processed with our product was exposed.
  • The website that was affected holds no customer area, no payment processing and no product data. It is a public-facing site presenting the company.
  • The compromised components were WordPress plugins on the website. They had no access path to the application.

If you are a customer of Libertify, this incident does not require any action in relation to your account.


What happened

On 29 July 2026, our website was temporarily compromised. Between 09:35 and 13:18 UTC (11:35–15:18 Central European Summer Time), some visitors were shown a counterfeit security verification page in place of our own pages, imitating a well-known service provider.

The page asked the visitor to copy a command and run it on their own computer, typically through the Windows “Run” dialog. That command installed software designed to steal passwords saved in the browser. It only worked on Windows.

The affected page is part of our public website. We do not operate a customer area or process payments on it, and our product runs on entirely separate infrastructure that was not affected.


Are you affected?

You may be affected if, on 29 July 2026 between 09:35 and 13:18 UTC, you visited our site and copied and ran the command the page presented. If so, the section below is for you.

If you did not run a command, no action is needed.


One further point, for completeness

Between 29 June and 29 July 2026, code from an unauthorised source was also being loaded into visitors’ browsers on our site. No action is required of you in relation to this, and nothing indicates that it affected your data.

We are mentioning it because we prefer to be complete rather than selective. In the interest of accuracy: because that code was fetched from an external server on each page view and never stored on our own systems, we cannot reconstruct what it did. Our checks found no evidence of any data being taken from our systems during this period, and no form on our site was submitted at any point in it.


If you ran the command

Treat your computer as compromised, and proceed in this order.

1. Deal with the machine first

Run a full antivirus scan. For most personal computers this is a reasonable first step. If the machine holds work or otherwise sensitive data, have it examined by a professional; where certainty matters, reinstalling the operating system is the only way to be sure it is clean.

2. Change your passwords from a DIFFERENT device

This is the critical point. Until the machine is clean, a new password typed on it can be stolen in turn. Use a phone or another computer.

3. Sign out of existing sessions

Changing a password does not always end sessions already open. In the security settings of your main accounts, use “sign out of all devices” or “revoke active sessions”.

4. Turn on two-factor authentication

On your email and any sensitive account. This is what makes a stolen password useless.

5. Watch your accounts

Over the coming weeks, look out for unfamiliar sign-ins, password reset emails you did not request, and transactions you do not recognise.

Need help? Visitors in France can use cybermalveillance.gouv.fr, the government service offering a free diagnostic and referrals to local providers. Elsewhere, your national cybersecurity agency or computer emergency response team will offer comparable guidance.


What we have done

  • Removed all malicious components and took the site offline on the day of detection
  • Reset every administrative credential and invalidated all existing sessions
  • Enabled two-factor authentication on all privileged accounts
  • Blocked component installation through the administration interface — the method the attacker used
  • Verified the integrity of the entire site, confirmed in production
  • Notified the French data protection authority (CNIL)

Regarding your personal data: our checks found no evidence of any data being extracted from our systems, and no data held in our application was within reach of this incident at any stage. Our contact database was examined across every channel capable of exporting data, over the whole period concerned, and no anomalous activity was recorded. No form on our site was submitted during the period concerned.


Contact us

For any question about this incident or about your personal data: privacy@libertify.com

We will respond to every enquiry.


This notice is published under Article 34 of the General Data Protection Regulation, the individuals concerned not being individually identifiable.