Security incident at OpenSprinkler.com (USA) – OpenSprinklerShop.de not affected

Important in advance: This security incident only affects the US website OpenSprinkler.com and the cloud services operated there. OpenSprinklerShop.de is not affected by this. Your customer, order and payment data stored by us is stored on a separate infrastructure in Germany and was never part of the incident.

Our partner OpenSprinkler (USA) informed us of a security incident on its servers on July 26, 2026. We are providing this information here in German because some of our customers may have also created an account directly with OpenSprinkler.com or used OpenSprinkler's cloud services.

What happened?

Between July 20th and 25th, 2026, an unauthorized person used a WordPress security vulnerability to gain administrative access to the server on which OpenSprinkler.com, OpenThings.io and OpenGarage.io be hosted. OpenSprinkler discovered the incident on the morning of July 26th, patched the vulnerability, rebuilt the server from a clean backup, and has confirmed that the attacker no longer has access.

The full announcement (in English) can be found here: Data Breach Notice – Action Required for All Customers.

OpenSprinklerShop.de is not affected

Once again to make it very clear: The incident affects the infrastructure of OpenSprinkler in the USA – not our shop. This includes your data at OpenSprinklerShop.de (name, address, orders, payment information). not affected.

Only data that was stored on US servers is affected - i.e. only if you:

  • your own account OpenSprinkler.com have created,
  • Cloud Sync have activated, or
  • a OpenThings Cloud (OTC) token have set up.

In these cases, the affected server contained your name, email address and a password hash; For Cloud Sync users, you also receive an encrypted copy of your controller connection settings.

What OpenSprinkler has already done

OpenSprinkler has invalidated all OpenSprinkler.com account passwords and is informing all affected users via email - starting with those who have an OTC token or have Cloud Sync enabled.

What you should do

If you have your own OpenSprinkler.com account or use Cloud Sync or OTC, we recommend that you follow the steps from the official notice:

  • Put yours OpenSprinkler.com password back.
  • Change that Password of your controller.
  • Renew yours OTC tokens.

If you do not use these services, you do not need to take any action.

Questions?

If you have any questions about the incident itself, please contact OpenSprinkler directly: support@opensprinkler.com. The official announcement and further information can be found here:

Of course, we will be happy to assist you if you have any questions.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.