Github Workflows Security Update - External Keys Must Be Rotated

Incident Report for OpenWater

Postmortem

S-RM has validated our findings by checking access logs from March 1 to May 5 for unauthorized or suspicious behavior.  We remain confident in our assessment that API keys were not used by an unauthorized party. This date range was chosen to provide significant data from the past to confirm and validate expected behavior patterns and confirm there was no significant deviation.

Further we have confirmed most customer systems are protected by IP address restrictions in addition to API Keys and that there is no further action for customers once the key rotation is complete.

In terms of after action we have determined our own use of CloudFlare enterprise which includes automatic bot detection and prevention, along with other defense in depth security strategy reduced the overall risk of this incident.

In terms of areas of improvement, OpenWater has also since implemented additional anti-phishing measures and additional security controls around developer code repositories.

Posted May 09, 2025 - 11:33 EDT

Resolved

On Friday, April 25th one of our developers clicked a phishing email which gave a bot access to certain integrations related code. Our developers do not have access to customer data and steps were taken immediately to close out access to potential unauthorized users. The developers do however have access to certain API keys used to integrate OpenWater with external CRM/AMS products.

As per proper security protocol, we are asking all impacted customers to rotate their API keys immediately. Our integrations support team is reaching out this week.

While our investigation is ongoing, at this time, we have found no evidence of code modifications, unauthorized access to production systems, exposure of customer data, or access to personal information. We are working with a third party, S-RM (https://www.s-rminform.com/digital-forensics-services) to validate our findings and we will update this article upon the conclusion.
Posted Apr 28, 2025 - 09:00 EDT