We experienced a security incident affecting customer account and order information. For customers who saved a payment card or used Cloud Sync, additional information may also have been affected.
On July 25, 2026, we discovered that an unauthorized party had exploited vulnerabilities in WordPress, the software running our websites, and had administrative access between July 20 and July 25. The affected server hosts OpenSprinkler.com, OpenThings.io, and OpenGarage.io.
We confirmed that the attacker retrieved data from the website database. The available logs cannot identify which customers or records were included. This notice is therefore intended for everyone whose information could have been involved, including customers who checked out as guests.
What You Should Do Now
Your OpenSprinkler.com account is the single sign-in for OpenSprinkler.com, OpenThings.io, and OpenGarage.io. The steps below apply to that one account, whichever site you use.
Everyone with an OpenSprinkler.com account should:
- Reset your password. Previous website passwords have been invalidated: Reset your password
- Change that password anywhere else you reused it.
- Watch for phishing. Scam messages may use your name, contact details, order history, or partial card information to appear convincing.
Everyone who used Cloud Sync with OpenSprinkler, OpenThings, or OpenGarage should also:
- Change the Device Password on each saved device.
- Replace your OpenThings Cloud (OTC) token. Create the replacement first, update your device and app, then revoke the old token — in that order, so you don’t lose remote access mid-way. Instructions
- Replace any HTTP authentication credentials you configured.
- Check your device settings — schedules or programs, port forwarding, and DDNS configuration — for anything you didn’t set.
We recommend the above steps for every Cloud Sync customer, regardless of password strength.
If your app asks for your previous account password when reconnecting Cloud Sync, that is expected. Your synchronized copy is encrypted with the password that was in use when it was last saved.
If you checked out as a guest: You do not have an OpenSprinkler.com password to reset. You should still be alert for phishing messages that use your name, email address, phone number, shipping address, or order details.
What Information May Have Been Involved?
The affected database contained OpenSprinkler.com account information, including names, email addresses, and password hashes.
WooCommerce order records — including orders placed without an account — contained information customers provided at checkout, such as names, email addresses, phone numbers, billing and shipping addresses, and order details.
If you saved a payment card to your account, the database also contained the card brand, last four digits, and expiration date. The full card number and security code were not stored in the affected database. These limited details cannot by themselves be used to make a purchase, but they could make a scam message appear more convincing.
We will never contact you and ask you to provide or confirm your card number, security code, website password, device password, OTC token, or HTTP authentication credentials. If a message asks for any of these — however convincing the details it cites — it is not from us.
For Cloud Sync customers, the database also contained an encrypted copy of saved device connection information. Depending on your configuration, this may have included:
- A device address, hostname, or URL
- A saved device credential. In some configurations this value can be used to access the device directly, without needing to recover the original password.
- An OpenThings Cloud (OTC) token
- HTTP authentication credentials, if you configured them
The encryption is derived from your OpenSprinkler.com account password and provides limited protection against an offline attack by someone holding a copy of the data. We have no evidence that anyone decrypted this information or used it to access a device, but we cannot rule it out. We recommend that every Cloud Sync customer complete the protective steps above, regardless of password strength.
What We Have Done
We replaced the affected server from a backup created before the unauthorized access, fully updated WordPress and the server software, removed the unauthorized accounts, invalidated website passwords and active sessions, rotated server-side credentials, and strengthened our monitoring and network protections.
Password Resets and Cloud Sync
Resetting your OpenSprinkler.com password protects access to your website account. It does not change your device password or OTC token, it does not by itself erase or re-encrypt an existing Cloud Sync copy on our server, and it cannot protect a copy of encrypted data that may already have been retrieved.
Please do not delete device configurations stored locally in your app or browser. Your local copy may be the only one you can still decrypt. If you delete it before the server-side copy is replaced, you may lose your configuration entirely. In the meantime, changing the device credentials and tokens listed above is the most important thing you can do to prevent older saved values from being used to access a device.
For assistance, visit OpenSprinkler Support.
We regret the concern and additional work this incident causes. Protecting customer accounts and devices is our immediate priority. We will update this post as additional confirmed information or Cloud Sync instructions become available.