ThreatPaper
Superseded

No client data, name or organisation was leaked in the CrowdSec breach

Assessment

CrowdSec's first public statement on September 17, 2026 said plainly: 'No client data, login/password, name, organization, or anything else was leaked,' and that the impact was limited to the company. Its own more detailed report the following day, September 18, superseded that: the leaked archive contained the email addresses of 83 CrowdSec users and the names, email addresses and investment context of 51 potential investors from a 2020 system, prompting the CEO to personally apologise to the investors. The first-day 'no personal data' claim was the company's own, and the company itself corrected it within 24 hours — so anyone repeating the September 17 reassurance is repeating a statement that was superseded by the September 18 report.

Where this claim appeared

CrowdSec (September 17 statement) · 2026-09-17

https://www.crowdsec.net/blog/crowdsec-statement-source-code-exposure

What “Superseded” means

Reported accurately at the time, then corrected by the original source. Recorded because the original version usually continues circulating long after the correction.

2 of 5 · rating scale

Assessed in

CrowdSec source-code leak: how the breach account changed in 24 hours, from 'no personal data' to 83 users

Think this assessment is wrong? Report an error.