No client data, name or organisation was leaked in the CrowdSec breach
Assessment
CrowdSec's first public statement on September 17, 2026 said plainly: 'No client data, login/password, name, organization, or anything else was leaked,' and that the impact was limited to the company. Its own more detailed report the following day, September 18, superseded that: the leaked archive contained the email addresses of 83 CrowdSec users and the names, email addresses and investment context of 51 potential investors from a 2020 system, prompting the CEO to personally apologise to the investors. The first-day 'no personal data' claim was the company's own, and the company itself corrected it within 24 hours — so anyone repeating the September 17 reassurance is repeating a statement that was superseded by the September 18 report.
Where this claim appeared
CrowdSec (September 17 statement) · 2026-09-17
https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposureWhat “Superseded” means
Reported accurately at the time, then corrected by the original source. Recorded because the original version usually continues circulating long after the correction.
2 of 5 · rating scale
Assessed in
CrowdSec source-code leak: how the breach account changed in 24 hours, from 'no personal data' to 83 usersThink this assessment is wrong? Report an error.