Security incident 2025.02 Action Required: Perform or complete credentials renewal processDear Joachim von Watt, Your API password must be changed. And if you haven't changed your website login password yet, that must be changed too. As we already informed you in February in connection with security incident 2025.02 from February 2025, your ASPSMS access data may be in the hands of unauthorized third parties.
 Screenshot: https://www.aspsms.com/en/apicredentials/
For this reason, it is imperative that you renew your access data for the ASPSMS system resp. SMSBLASTER. Information about the security incidentAvoid account suspensionWe automatically suspend accounts that are actually being misused by unauthorized parties. In such cases, the account will remain suspended until you have changed your API password and confirmed the successful change to us by email or phone. Only then will the account be reactivated. Please note: A suspension usually means a lot of work for you, as your ongoing operations are unexpectedly interrupted. If your password has been compromised but your account has not yet been misused, there will be no automatic suspension for the time being. This gives you the opportunity to renew your API password in good time and at your own pace. This ensures that your SMS messaging continues to run smoothly at all times. Important noteWe have noticed that some customers changed their API password after thesecurity incident, but then reset it back to the old, compromised value.This means that attackers still have access. As a result, cases of abuse have already been observed in whichattackers sent phishing SMS messages via customer accounts thathad done exactly that or had not yet changed the API password. This not only leads to direct costs for you as a customer, but also jeopardizes ourreputation with our mobile communications partners.
Credentials Renewal process- Step 1: Change Website Login Password (if not already done)
- Step 2: Change API Password
- Step 3: Completing the renewal process
Do a Website Login on the ASPSMS Website with your ASPSMS account email address e.g. welcome@vadian.net to complete the Credentials Renewal process:
https://www.aspsms.com/en/login/?USEREMAIL=welcome@vadian.net Important- Do not reuse a previous password under any circumstances.
- Ensure that the new API password is correctly stored in your software.
- If you use ASPSMS via a third-party system, the new API password must also be stored there - otherwise, SMS messaging will no longer work.
If you have any further questions, or if you need support with the renewal process, we will of course be happy to help you directly. Kind regards,
Till Christian Bannwart Chief Information Security Officer Member of the Executive Board
VADIAN.NET AG Katharinengasse 10 9000 St. Gallen Switzerland
Phone: +41 71 246 56 56 Email: keyaccounts@aspsms.com
Customer Service Your ASPSMS Support Phone: +41 71 246 56 56 Email: support@aspsms.com
|