Third Party Supply Chain Incident

Security update

June 19, 2026 (last updated August 10)

This incident is now closed. The investigation is complete, remediation has been independently verified and steps have been taken to reduce the risk of future incidents. The summary below reflects our final updates.

We were made aware in June of a supply-chain security incident involving a third-party provider used by Digital Science alongside other well known, global organizations.

What we know. An unauthorized party compromised the provider’s systems and, through its standard integration with our CRM platform, was able to access a limited set of our CRM data such as business contact information (e.g. names, email addresses, phone numbers) and sales opportunity metadata (e.g. contract start / end dates, company names and addresses). Access to our data occurred during a brief window between June 11 and June 12, 2026.

The provider’s own investigation, supported by an independent forensic review carried out by CrowdStrike, has now concluded. The root cause has been traced to a credential shared by the provider with one of its own infrastructure suppliers. The forensic review found no evidence of unauthorized activity within the provider’s environment after June 12, 2026, and no evidence that systems beyond those tied to the integration service were accessed.

To confirm, Digital Science products and associated data have not been impacted by this incident and remain fully operational and secure. No valid product access credentials, payment card or sensitive data of any of our customers, prospects or users is known to have been accessed. We have seen no evidence of misuse of the information involved.

What we’ve done. Upon becoming aware of the incident, we immediately disabled all connections to the third-party provider from our systems. We engaged our internal security experts alongside external breach response services via our cyber insurance. A full investigation was conducted with ‘indicators of compromise’ from the vendor and external security organizations, and our IT and infrastructure teams blocked all such indicators of compromise across our internal and product infrastructure. This included the blocking of IPs and email domains believed to be associated with the attacker, alongside the implementation of other technical controls. A review was completed of all CRM integrations and, as an additional precaution, all integration credentials were refreshed. Affected customer contacts were identified and contacted directly.

What we know about the provider’s remediation. Before any integration was restored, the provider was required to pass security reinstatement reviews by its integration partners, including our CRM platform vendor. The measures the provider has implemented include dedicated controls for each integration, fixed outbound IP addresses allow-listed by its partners, platform-wide enforcement of modern authorization standards, tightened credential lifecycles, the removal of long-lived personal access tokens in favour of short-lived automatically expiring credentials, centralised monitoring and detection and response, and network filtering controls across its deployment pipelines. These measures have been independently verified by CrowdStrike, whose final report is available to the provider’s customers.

What happens next. We consider this incident closed and no further updates to this page are planned. We continue to monitor for anomalous activity across our estate as part of business as usual. A post-incident review is scheduled and lessons identified will be fed into our continuous improvement programme.

What we ask of you. As always, please remain vigilant about any correspondence that appears to come from Digital Science but does not reach you through our standard channels, particularly if you are asked to make a payment or to change existing business information you hold about us. If any communication from us seems unexpected or unusual, verify it with your main Digital Science contact before responding or sharing information.

We understand and appreciate the trust our customers place in Digital Science, and we are grateful for the patience shown by those affected. 
If you have any questions, please direct them to: ds-sec-comms@digital-science.com.