Currencycloud incident
Password and Security Reset on Prod Environment
Currencycloud experienced a minor incident on June 16, 2025 affecting Paydirect.io / Direct, lasting 1h 26m. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- investigating Jun 16, 2025, 05:49 PM UTC
The DIRECT website is currently up and running. However, we are aware that some customers are experiencing difficulties resetting their passwords and security questions after receiving a password expiry email, thus unable to login to DIRECT in the production environment. Our teams are actively working to resolve this issue.
- resolved Jun 16, 2025, 07:15 PM UTC
This incident has been resolved.
- postmortem Jun 17, 2025, 04:31 PM UTC
# Incident Summary As part of our ongoing commitment to improving platform security, we introduced a 90-day password expiry policy earlier this year, following a security recommendation identified in a routine assessment. This policy was applied to both our Demo and Production environments on March 18, 2025. On June 16, 2025, the first 90-day cycle reached its end. While customers received standard expiry notifications in advance, a significant number encountered issues resetting their passwords—largely due to difficulties recalling answers to security questions set up some time ago. This led to a surge in support requests, affected by expired passwords. # Resolution To assist we have implemented a temporary 30-day extension to all affected passwords to restore immediate access and reduce support friction. In addition to providing additional guidance and support for password resets and security question recovery through our 1st-line support team. Thank you for your patience as we worked to address the issue. Your security remains our top priority, and we’re committed to delivering both strong protection and a seamless user experience. If you're still experiencing any issues accessing your account, please don't hesitate to contact our support team directly. #### Currencycloud Confidential