Our partner OpenSprinkler (USA) informed us of a security incident on its servers on July 26, 2026. We are providing this information here in German because some of our customers may have also created an account directly with OpenSprinkler.com or used OpenSprinkler's cloud services.
What happened?
Between July 20th and 25th, 2026, an unauthorized person used a WordPress security vulnerability to gain administrative access to the server on which OpenSprinkler.com, OpenThings.io and OpenGarage.io be hosted. OpenSprinkler discovered the incident on the morning of July 26th, patched the vulnerability, rebuilt the server from a clean backup, and has confirmed that the attacker no longer has access.
The full announcement (in English) can be found here: Data Breach Notice – Action Required for All Customers.
OpenSprinklerShop.de is not affected
Once again to make it very clear: The incident affects the infrastructure of OpenSprinkler in the USA – not our shop. This includes your data at OpenSprinklerShop.de (name, address, orders, payment information). not affected.
Only data that was stored on US servers is affected - i.e. only if you:
- your own account OpenSprinkler.com have created,
- Cloud Sync have activated, or
- a OpenThings Cloud (OTC) token have set up.
In these cases, the affected server contained your name, email address and a password hash; For Cloud Sync users, you also receive an encrypted copy of your controller connection settings.
What OpenSprinkler has already done
OpenSprinkler has invalidated all OpenSprinkler.com account passwords and is informing all affected users via email - starting with those who have an OTC token or have Cloud Sync enabled.
What you should do
If you have your own OpenSprinkler.com account or use Cloud Sync or OTC, we recommend that you follow the steps from the official notice:
- Put yours OpenSprinkler.com password back.
- Change that Password of your controller.
- Renew yours OTC tokens.
If you do not use these services, you do not need to take any action.
Questions?
If you have any questions about the incident itself, please contact OpenSprinkler directly: support@opensprinkler.com. The official announcement and further information can be found here:
Of course, we will be happy to assist you if you have any questions.
