Security notice: fake verification pop-up on easee.com

Published: 22/09/2026

If you visited easee.com on a Windows computer between 17 and 18 September 2026 and
were asked to copy a command and paste it into Windows Terminal, please read this.

What happened:

Between 17 and 18 September 2026, unauthorised code on easee.com displayed a fake
Cloudflare verification window to some visitors using Windows. The window asked visitors to
copy a command and paste it into Windows Terminal or the Windows Run dialogue.
The command was not ours. Anyone who ran it is likely to have installed malicious software
on their own computer.
The code was removed on 18 September 2026 and the website has been checked and
confirmed clean.

Who is affected

Only visitors using Windows during that period who were shown the window and followed its
instructions.
If you simply visited easee.com and did not copy and run a command, nothing was installed
on your computer. The pop-up could not install anything by itself, it required the visitor to
run the command manually.

What to do if you ran the command

Assume your computer is compromised and treat it as such until checked.
Run a full scan with up-to-date antivirus or anti-malware software. If you use a work
computer, contact your IT department instead and tell them what happened.
Change any passwords you entered on that computer after 17 September 2026 and do it from
a different device you know is clean, not from the affected machine.
Enable two-factor authentication on your important accounts if you have not already.
Watch for unexpected account activity, unfamiliar sign-ins and unusual payment card
transactions.

Possible consequences

Software of this kind is commonly used to steal saved passwords, browser session data and
other information held on the affected computer. We cannot see what was installed on any
individual machine or what it may have collected, which is why we ask you to take the steps
above.

What we have done

We removed the malicious code, cleared all caching and verified the website. We have carried
out a full technical investigation with our website supplier, closed the weaknesses that
allowed the attack, replaced the affected credentials, and put nightly security monitoring in
place. We have preserved the evidence and reported the attacker’s infrastructure to the
relevant providers.
We have notified the Norwegian Data Protection Authority (Datatilsynet).

CONTACT

Questions about this notice: gdpr@easee.com