Scareware on Marketing Website
Last updateresolvedSep 4 · 03:46 UTC
At approximately 5:03 AM PT, September 3, 2026, a malicious actor accessed Artera’s marketing website (Artera.io) and installed a malicious WPCode Snippet that injected a fake Windows Defender tech-support scam iframe into the artera.io homepage. This caused some visitors to experience pop-ups of a fake Windows Defender security alert. Artera’s security team located the malicious plugin, eradicated the “scareware” from Artera.io and worked with the third party WordPress team to harden access to the Artera marketing website by 10:30 AM PT. The marketing website is separate from our production platform. After careful investigation, we have found no evidence that Artera products were infiltrated, data were accessed, or PHI or PII were accessed. What is the Scareware’s Impact: - If a visitor viewed the fake alert only, there is no compromise. - If a visitor clicked on the fake alert, the browser may have locked and triggered a malicious file download. - If a visitor called the number, the scammer who answered may have tried to “social engineer” the caller to install a remote-access software, then the scammer may have tried to use that remote access to install a trojan to steal or extract data. Why are we sharing this update? We believe in being proactive and transparent about cyber security. Any visitors to Artera.io on, September 3, 2026 from 5:03 AM PT to 10:30 AM PT who interacted with this scareware, such as clicking on it or calling the phone numbers, could be compromised. We are proactively reaching out to the organizations whose IP addresses we can identify who visited our marketing website during the incident window.
Reported by Artera on their status page.
