Security Incident

Update – 5 August 2026

This update supersedes our statement published on 31 July 2026 which can be found at the end of this post.

Adform provides advertising technology used by many websites and other digital services. We are publishing this updated notice for people who may have visited a website using affected Adform technology during the recent security incident.

What happened?

On 27 July 2026, at 03:00 CEST Adform detected suspicious activity and immediately began an investigation. Retrospective log analysis has shown that the first malicious activity occurred on 26 July at 23:49 CEST. We contained the incident, removed the malicious code, and took further steps to protect website visitors, our clients, and the Adform platform.

We have not seen further distribution of the malicious code since 19:16 CEST on 27 July 2026.

The malicious code was designed to interfere with certain cryptocurrency transactions involving Bitcoin, Ethereum, or Tron. It could attempt to replace a cryptocurrency wallet address displayed, entered, copied, or pasted while an affected webpage was open.

To our knowledge, the code was not designed to install software on a user's device or remain on the device. It operated only while an affected webpage was open.

What have we learned since then?

As part of our continuing investigation, Adform confirmed additional technical information at 15:47 CEST on 3 August 2026.

Our review shows that an affected Adform script ran on certain webpages served over HTTP. The script attempted to make an outbound request to infrastructure believed to have been operated by, or accessible to, the threat actor.

On webpages served over HTTPS, the browser prevented this request from completing. This protection would not have applied when a webpage was served over HTTP. We therefore cannot rule out that the request completed for some affected HTTP webpages.

If the request completed, the receiving infrastructure could have seen:

  • the website hostname;
  • the path of the webpage being visited; and
  • the source/public IP address associated with the request.

This means we cannot rule out that IP addresses associated with some visitors to affected HTTP webpages were visible to the threat actor. We do not know that this happened in every case.

Based on the information currently available, we have not found evidence that the script transmitted webpage content, information entered by users, account credentials, or other data fields beyond the hostname, webpage path, and source/public IP address described above.

The incident has been contained, and Adform's services are safe to use. Our investigation remains ongoing, and we continue to strengthen our security measures.

What does this mean for website visitors?

The incident may have affected people who visited a website using affected Adform technology on 27 July 2026.

The potential disclosure of website hostnames, webpage paths, and source/public IP addresses concerns affected webpages served over HTTP. Based on our current technical assessment, the relevant outbound request was prevented from completing when an affected webpage was served over HTTPS.

As browsers may temporarily store website code, we recommend that people who visited an affected website clear their browser cache as a precaution.

If you displayed, entered, copied, or pasted a Bitcoin, Ethereum, or Tron wallet address while an affected webpage was open, please check the wallet address and any relevant transaction information for discrepancies.

What have we communicated to Adform clients and partners?

Using the technical information available to us, we have sought to identify and notify relevant affected parties. This includes:

  • advertisers using affected Adform Site Tracking technology on webpages served over HTTP;
  • publishers operating HTTP digital properties on which affected Adform advertising technology ran; and
  • other relevant contractual partners.

We have provided relevant parties with information and recommended actions to support their legal, privacy, and security assessments. Because the available technical information may not allow every affected relationship or webpage to be identified with certainty, we are also publishing this notice to make the information more widely available.

On August 5, 2026, Adform notified the Danish Data Protection Authority (Datatilsynet) concerning the potential impact on personal data stemming from the HTTP-related incident. Adform has also reported the broader security incident to other relevant authorities.

We will continue to cooperate with our clients, contractual partners, and the authorities. We will provide further information if our investigation identifies material new findings.

We apologize for any concern or inconvenience caused.

For questions about this incident, please contact [email protected].

* 7 August 2026: Exact timings for the start of the incident have been added to this statement.

 

──────────────────────────────────────────────── 

  

 

Original statement – 31 July 2026

Adform provides advertising technology services used by many websites and other digital properties. We are publishing this notice to provide clear information to individuals who may have visited a website using Adform technology during a recent security incident.

What happened?

On 27 July 2026, Adform detected suspicious activity and immediately launched an investigation under its incident-response procedures. Once the cybersecurity threat was confirmed, we contained the incident, removed the malicious code, and took further measures to protect website visitors, our clients, and the Adform platform.


The malicious code was designed to interfere with certain cryptocurrency transactions involving Bitcoin, Ethereum, or Tron by attempting to replace a cryptocurrency wallet address copied to a user’s clipboard with a different address.


To our knowledge, the code was not designed to install software on a user’s device or establish persistence. It operated only while an affected webpage was open.


Based on our investigation to date, we have found no evidence that the malicious code transmitted users’ IP addresses or information about the websites they visited to an external party. Technical analysis indicates that such transmission may have been possible, and this aspect remains under investigation.


The incident has been contained, and Adform’s services are safe to use. Our investigation remains ongoing, and we continue to strengthen our security measures based on our findings.


What does this mean for website visitors?


The incident may have affected individuals who visited a website using the affected Adform technology on 27 July 2026.


As browsers may temporarily store website code, we recommend that individuals who visited an affected website clear their browser cache as a precaution. 


This will clear the affected code from your browser. If you copied a Bitcoin, Ethereum, or Tron wallet address while one of the affected pages was open, please take a moment to check the address before you complete the transaction. It's a quick step, and it's worth doing.


What does this mean for Adform clients?


Adform has informed affected clients through dedicated communications and provided them with relevant information and recommended actions.


Clients should follow the guidance provided by Adform, clear any relevant caches under their control where applicable, and assess whether additional communication to their website visitors is appropriate.


The incident has been reported to the relevant authorities. We will continue to cooperate with our clients and the authorities and provide further information where appropriate.


We apologise for any concern or inconvenience caused.


For questions relating to this incident, please contact our support team at [email protected].