Security incident — August 2026

Last updated: 25 August 2026

What happened

On 20 August 2026, our print subscription portal (print.ventor.tech) was hit by a ransomware attack. The attacker exploited a vulnerability in a third-party infrastructure management tool and encrypted the portal's database. The attack lasted a few minutes. We secured the environment immediately afterwards and took the portal offline.

This affected the print portal only. It is a separate incident from the one affecting ventor.app earlier in August, which we notified customers about separately.

What this meant for you

Printing was never interrupted. Print jobs are processed through our printing partner's infrastructure, which was not involved. Customers who were printing before the incident continued printing throughout.

The portal itself was unavailable while we rebuilt it. During that time you could not sign in, view usage, retrieve credentials, or manage your subscription.

Your subscription and billing were unaffected. Payments are handled by Stripe. No payment card or banking data is stored on our systems, and none was involved.

What data was in the affected database

Name, email address, company name and VAT number, billing country, subscription and printing history, and the credentials your print client applications use to connect.

Portal passwords were stored as salted hashes, not in readable form.

The evidence we have indicates the attack was aimed at encrypting data for extortion rather than copying it, and we found no indication that data was extracted. However, the attacker had access to the environment, and we are not prepared to rely on the absence of evidence. We are treating the credentials as potentially exposed, which is why we are asking every customer to replace them.

What we are asking you to do

Please be alert to phishing

Incidents like this are often followed by messages imitating the affected company.

  • Genuine emails from us come only from an @ventor.tech address.
  • We will never ask you to send a password or API key by email or chat.
  • We will never ask you to make a payment to restore access to your account.

Forward anything suspicious to support@ventor.tech rather than replying to it.

What we did

We rebuilt the portal from scratch on clean infrastructure rather than restoring the compromised system. Credentials are no longer stored in a form that could be reused if a database were ever exposed again, database access is limited to the minimum each component needs, and backups are now verified by restoring them rather than only by creating them.

Some print history from before the incident could not be recovered. Where that is the case, your usage charts say so rather than showing zero.

Current status

The portal is operating normally. If anything is not working as you expect, or you have questions about the incident, contact us at support@ventor.tech.