We identified unauthorised access to one of our application servers. The emerge was contained and the server was rebuilt. The system involved did not store customer data, and no data breach occurred. no activity is required from you.
All customer account information, including your email destination and hashed password, is stored in a separate database that remained protected throughout the incident. We reviewed application, network, and database audit logs for the full period. These substantiate that the attacker did not access, query, or copy any customer data. defrayal card information is not stored on our systems and was never at risk.
At 19:46 UTC on friday 5 december 2025, an attacker reached ace application server through an incorrectly exposed network path and triggered a flaw that allowed a command to run, causing the server to halt responding. The server restarted repeatedly due to automatic recovery, resulting in intermittent service disruption. The incident was contained at 02:17 UTC on saturday 6 december 2025. Some services, including checkout, remained disrupted for a further twenty-four hours while we applied changes across our infrastructure.
We corrected the network publication that allowed direct access and patched the software vulnerability on the affected server. Based on all evidence, no customer data was accessed.