CubePilot, the Aussie makers of drone autopilots and navigation gear, just got an unwanted backstage pass into their systems: on July 24 their domain was hijacked, and for a short window attackers rerouted traffic to malicious infrastructure. That means people who thought they were logging into CubePilot services might have been talking to a facsimile — complete with shiny-looking HTTPS locks.

What happened

In plain terms, the bad actors took over the cubepilot.org DNS records, which let them steer visitors to servers they controlled. To make things even sneakier, the attackers managed to obtain valid TLS certificates for the affected subdomains, so browsers showed normal-looking secure connections while the traffic was actually being intercepted.

The consequences: credentials entered on services like the company portal and community forum on July 24 may have been captured. CubePilot says they regained control of their domains that same day, revoked the fraudulent certificates, saved logs and evidence, notified upstream providers, and reported the event to the Australian Cyber Security Centre and law enforcement.

Several public-facing services — OEM pages, the community forum and documentation portal — were taken offline while the investigation proceeded. The company also temporarily disabled its ERP portal as a precaution. They’ve promised to contact anyone directly if they confirm an impact.

What you should do (short checklist)

If you used any CubePilot services around July 24, or you reuse passwords between sites, take these steps pronto:

  • Assume credentials entered on July 24 could be compromised and change passwords on affected accounts and anywhere the same password is reused.
  • Don’t flash firmware images downloaded on July 24–25 until CubePilot finishes integrity checks. Firmware downloaded before July 24 is reported as safe.
  • Be suspicious of payment requests that claim to be from CubePilot — verify them by calling your usual contact before sending money or details.
  • Monitor accounts tied to CubePilot services for unusual activity and enable multifactor authentication where available.

In short: this was a textbook DNS-level interception — ugly, fast, and capable of bypassing visual HTTPS cues. Treat any credentials or downloads from the affected window as suspect, and follow the checklist above. CubePilot appears to have taken containment and reporting steps, but the usual rule applies: assume compromise and act quickly.