Phani Puttabakula - August 4, 2026

Infrastructure Security Update: Unauthorized Access Identified and Contained

During routine infrastructure monitoring, our engineering team identified unauthorized activity on one of our internal administrative servers. We acted quickly to contain it, and we want to be transparent about what we found, what we did, and where things stand.

This kind of post is not comfortable to write. But we think being honest about security incidents — including ones that turn out to be contained — is the right thing to do.


What We Found

Our monitoring flagged unusual process activity on an internal server used to manage infrastructure. When we investigated, we found that a valid internal account had been compromised and was being used to run unauthorized software on that machine.

We have not yet determined how the account was initially compromised. That is part of our ongoing investigation.

What we can say is that our current evidence is consistent with unauthorized resource usage — specifically, the kind of background activity associated with cryptocurrency mining — rather than any attempt to access or extract data. We have found no evidence that customer data was accessed or exfiltrated. We want to be clear, though: our forensic review is not complete, and we will update this post if our investigation changes that picture.


What We Did Immediately

As soon as we identified the unauthorized activity, we moved to contain it:

  • Terminated the unauthorized processes running on the affected server
  • Revoked the compromised account’s access and disabled it entirely
  • Rotated credentials and SSH access across our infrastructure
  • Reviewed and tightened firewall rules on the affected system

None of those steps waited for a full investigation to conclude. The moment we confirmed something was wrong, we closed the access and started cleaning up.


What We Are Doing Now

Containment was the first step. The longer work is making sure nothing like this can go unnoticed or unaddressed in the future.

We are rebuilding the affected administrative server from a clean, known-good state rather than trying to patch or restore it in place. It is a slower path, but it means we know exactly what is running on that machine when it comes back.

We are also conducting a full review of our access-control practices — looking at which accounts have administrative access, how credentials are stored and rotated, and where our monitoring coverage has gaps. The compromised account had a window of roughly two days before we detected the activity. We want to understand what it could have reached during that time, and we want to shrink that detection window considerably going forward.


What We Still Do Not Know

We are trying to be careful here not to overstate our confidence.

We do not know how the account was compromised. Possibilities include a leaked or reused password, a phishing attempt, or something else — but we have not pinned it down.

We have not completed a review of everything the account could have accessed. It had administrative privileges on the affected server, and that server had network reachability to other parts of our infrastructure. We are working through what that means systematically.

“No evidence of data exfiltration” is based on what we have reviewed so far, not on a completed forensic conclusion.

We will be transparent if any of that changes.


Why We Are Sharing This

There is a version of this where we say nothing publicly unless we find something that triggers a specific notification obligation. We considered it.

We chose not to go that route. Security incidents happen to organizations that are paying attention and to ones that are not. We were paying attention. We caught this through routine monitoring, acted within the same day, and have been working on the investigation and remediation since. We think sharing what we know — including the parts that are still uncertain — is more consistent with how we want to operate than staying quiet.

If you have questions or concerns, reach out to us directly at security@bluefunda.com. We will keep this post updated as our investigation progresses.

Share this article
LinkedIn