Supply chain β›“ Supply Chain

Pi-hole Third-Party Breach (August 2025)

πŸ“… 2025-08-01 🏒 GiveWP WordPress
Primary Source β†—

Incident Details

Pi-hole discloses data breach triggered by WordPress plugin flaw. Pi-hole, a popular network-level ad-blocker, has disclosed that donor names and email addresses were exposed through a security vulnerability in the GiveWP WordPress donation plugin. Pi-hole acts as a DNS sinkhole, filtering out unwanted content before it reaches the users’ devices. While initially designed to run on Raspberry Pi single-board computers, it now supports various Linux systems on dedicated hardware or virtual machines. The organization stated that they first learned of the incident on Monday, July 28, after donors began reporting that they were receiving suspicious emails at addresses used exclusively for donations. Third-party company: GiveWP WordPress.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
GiveWP WordPress
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-08-01 Breach occurred
  2. 2025-08-01 Publicly disclosed