Security incident — August 2026
Last updated: 25 August 2026
What happened
On 20 August 2026, our print subscription portal (print.ventor.tech) was hit by a ransomware attack. The attacker exploited a vulnerability in a third-party infrastructure management tool and encrypted the portal's database. The attack lasted a few minutes. We secured the environment immediately afterwards and took the portal offline.
This affected the print portal only. It is a separate incident from the one affecting ventor.app earlier in August, which we notified customers about separately.
What this meant for you
Printing was never interrupted. Print jobs are processed through our printing partner's infrastructure, which was not involved. Customers who were printing before the incident continued printing throughout.
The portal itself was unavailable while we rebuilt it. During that time you could not sign in, view usage, retrieve credentials, or manage your subscription.
Your subscription and billing were unaffected. Payments are handled by Stripe. No payment card or banking data is stored on our systems, and none was involved.
What data was in the affected database
Name, email address, company name and VAT number, billing country, subscription and printing history, and the credentials your print client applications use to connect.
Portal passwords were stored as salted hashes, not in readable form.
The evidence we have indicates the attack was aimed at encrypting data for extortion rather than copying it, and we found no indication that data was extracted. However, the attacker had access to the environment, and we are not prepared to rely on the absence of evidence. We are treating the credentials as potentially exposed, which is why we are asking every customer to replace them.
What we are asking you to do
Two things, and they are independent — do them when it suits you.
Replace your PrintNode Client password. Nothing stops working when you do this. Your computer stays connected and printing continues. You will need the new password only if you sign the PrintNode Client out and back in — your printers and their settings are preserved when you do.
Replace your API key — but let us do it. Your Odoo module stops sending print jobs the moment the old key is revoked. Entering the new key from the module’s own settings deletes the printers and print rules it keeps in Odoo and clears everything that points at them — report policies, scenarios, buttons and default printers — so printing stays broken until all of it is configured again. Email support@ventor.tech and we will change the key for you with your settings intact. On the printing service itself nothing changes: your computer, the printers registered on it and the desktop Client are unaffected.
The password you can replace yourself, from your Direct Print credentials page — sign in and you will see what still needs replacing. For the API key, write to us and we will arrange a time.
Please be alert to phishing
Incidents like this are often followed by messages imitating the affected company.
- Genuine emails from us come only from an @ventor.tech address.
- We will never ask you to send a password or API key by email or chat.
- We will never ask you to make a payment to restore access to your account.
Forward anything suspicious to support@ventor.tech rather than replying to it.
What we did
We rebuilt the portal from scratch on clean infrastructure rather than restoring the compromised system. Credentials are no longer stored in a form that could be reused if a database were ever exposed again, database access is limited to the minimum each component needs, and backups are now verified by restoring them rather than only by creating them.
Some print history from before the incident could not be recovered. Where that is the case, your usage charts say so rather than showing zero.
Current status
The portal is operating normally. If anything is not working as you expect, or you have questions about the incident, contact us at support@ventor.tech.