Cyber Incident Victim: PagerDuty
Date:
Jul 2015
Location:
United States of America
Summary
PagerDuty experienced an unauthorized intrusion where an attacker bypassed multiple authentication layers to access a replica database containing customer information, including names, email addresses, salted and peppered password hashes, and public calendar feed URLs. The company contained the breach within hours, enhanced monitoring and system hardening, and mandated password resets for all customers while advising them to reset calendar URLs and reauthorize linked mobile devices; the password hashing implementation made credential compromise computationally infeasible as the pepper remained secure.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 9, 2015, PagerDuty detected an unauthorized intrusion into its systems after an attacker bypassed multiple layers of authentication to gain access to an administrative panel provided by one of the company’s infrastructure providers. The attacker leveraged this access to log into a replica of one of PagerDuty’s databases, compromising customer information including names, email addresses, hashed passwords, and public calendar feed URLs. The company contained the breach within hours of detection, terminating the attacker’s access and initiating immediate mitigation efforts. PagerDuty’s investigation confirmed the attacker accessed hashed passwords protected with both a salt and a pepper, though the pepper remained uncompromised, making password decryption computationally infeasible. Public calendar feed URLs, which provided read-only access to users’ on-call schedules, were also exposed but did not grant further system access.

PagerDuty publicly disclosed the incident on July 30, 2015, mandating a password reset for all customers effective August 3 and advising users to reset calendar feed URLs and revoke mobile device access linked to their accounts. The company enhanced its monitoring, detection capabilities, and system hardening measures following the breach. No evidence indicated misuse of the compromised data, but the incident impacted all customers, necessitating widespread credential updates. PagerDuty emphasized the layered security measures protecting passwords while acknowledging the exposure of limited personal information. The response focused on containment, transparency, and preventive infrastructure improvements to address the intrusion vector exploited through the third-party administrative panel.
