Notice history
Jun 2026
No notices reported this month
May 2026
- PostmortemPostmortem
Composio security incident — May 21, 2026
On May 21, 2026, Composio — one of the integration providers Spinnable uses to connect to third-party services — experienced a security incident. Composio's own analysis indicates the affected scope was small (around 0.3% of customer connections globally, concentrated in GitHub, which Spinnable does not route through Composio).
Impact on Spinnable
We have no indication that any Spinnable accounts have been impacted. The connections that route through Composio (Gmail, Outlook, Asana, and similar) are stored on Composio's infrastructure, not ours — so our exposure tracked theirs. Integrations Spinnable provides through other MCPs or directly are not part of this incident.
We reviewed our access logs for activity from the attacker's known IP addresses across the incident window and found no evidence of unauthorized access to Spinnable systems.
What we did
Out of an abundance of caution, every affected connection in our project has been invalidated — either through Composio's own bulk-revocation effort, by per-connection revocation we ran through their API, or through direct credential rotation (X / Twitter) where Composio's revocation pathway was failing. Affected users were notified directly by email.
Timeline (UTC)
When
Event
May 21, 08:05–16:15
Composio incident window
May 23
Composio published their public disclosure and began bulk revocation
May 24
Spinnable forensic snapshot, per-connection revocation for our project, X (Twitter) client-secret rotation
May 26
Post-mortem published; status page updated
May 27
Spinnable emailed the affected users directly
What we've improved
Enabled 2FA on Spinnable's Composio dashboard account
Configured IP allowlisting on the Composio API key (a feature Composio rolled out as part of their incident response)
Reorganised our public status-page components to separate Spinnable services from subprocessors, so the same kind of upstream incident attributes correctly in future
Committed the response tooling (snapshot → resolve users → revoke → comms) to the Spinnable repo for faster future runs
Looking forward
For toolkits where token leakage would be high-impact, we're evaluating moving to bring-your-own OAuth credentials, which would give Spinnable a direct kill switch independent of subprocessor cooperation. We'll share updates as that work progresses.
Reference
Composio's full public disclosure: https://composio.dev/blog/composio-may-2026-security-incident
Questions or concerns: security@spinnable.ai
- ResolvedResolved
This incident has been resolved. All tools should be working correctly after reconnection.
We will notify users by email in the coming day with more details about the causes and measures taken.
- MonitoringMonitoring
We implemented a fix and are currently monitoring the result. We will email users individually to explain the actions taken and the disruption they saw with some of their connected accounts.
- InvestigatingInvestigating
We are currently investigating an incident with an upstream provider of tools for workers.
Apr 2026
- ResolvedResolved
This incident has been resolved.
- MonitoringMonitoring
We believe all users affected by this particular issue have been resolved. The team is going to keep an eye on these error rates to ensure we catch any that didn't originally appear, or that no new issues arise.
We appreciate your patience as we worked through this issue.
- UpdateUpdate
The team is continuing their mitigation efforts. We've fixed and restarted most of the affected projects. We're continuously looking for any others that are affected so we can be sure to get them all fixed.
- UpdateUpdate
The team is still working to bring these back online, and have a fix under way.
Many users can also resolve this on their own via a project restart. This can be performed from the dashboard for your own projects at any time. But for those who are still seeing issues after a restart, we will be pushing a fix soon.
- UpdateUpdate
We have identified this issue across multiple regions, not just eu-west-3 as originally suspected. We are expanding the scope of efforts to bring affected projects back online.
Users can also resolve this, in most cases, on their own via a project restart. This can be performed from the dashboard for your own projects at any time.
- UpdateUpdate
The team is continuing to work through affected projects; however, a project restart is also effective. This can be performed from the dashboard for your own projects at any time.
- IdentifiedIdentified
We are seeing an increase in projects unavailable in eu-west-3 following an upstream issue with EC2 instances in the region. The team is working on restoring access to these projects