CubePilot Drone Maker Hijacked at the DNS Level, Passwords and Firmware in Doubt

Attackers seized control of cubepilot.org on July 24, issued valid HTTPS certificates for every subdomain, and intercepted traffic to the login portal and forum before the Australian firm clawed the domain back.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • CubePilot, an Australian maker of drone flight controllers, lost control of its cubepilot.org domain on July 24, 2025, in a DNS hijacking attack.
  • The attackers obtained valid TLS certificates covering every cubepilot.org subdomain, meaning the login portal and community forum looked legitimate while routing to attacker servers.
  • Any password entered on CubePilot services on July 24 should be considered captured, and reused passwords should be changed everywhere.
  • Firmware images downloaded on July 24 or 25 should not be flashed to drones until CubePilot finishes checking them; anything downloaded before July 24 is treated as safe.
  • The incident has been reported to the Australian Cyber Security Centre and law enforcement, and OEM services, the forum, the documentation portal and the ERP system remain offline.

CubePilot, the Australian company that builds the autopilot boards guiding many commercial and military drones, has told customers its website was hijacked at the internet's address-book level on July 24.

The attack is what security engineers call DNS hijacking. Every website has a domain name (like cubepilot.org) and a Domain Name System record that tells browsers which server to actually connect to. Take over that record and you can quietly send everyone typing the real address to a server you control.

That is what happened here. For a window on July 24, visitors to CubePilot's login portal and community forum were reaching machines run by the attacker, not the company.

Why the padlock did not help

The attacker also got working HTTPS certificates. These are the small files that make a browser show the padlock icon and say a site is secure. Because the attacker controlled the domain, a certificate authority issued genuine certificates covering every cubepilot.org subdomain. To any customer, the fake pages looked identical to the real ones, padlock and all.

"The certificates obtained by the attacker covered every cubepilot.org subdomain, so credentials entered on any of our services on 24 July may have been captured, the portal and the forum included," the company said in its status update.

CubePilot's blunt advice: "If you used the same password anywhere else, change it there now."

Who is CubePilot and why does this matter?

CubePilot designs the small computers that fly drones. Its hardware sits inside aircraft used for surveying, agricultural spraying, search and rescue, and, increasingly, defence and government work. The company has publicly backed Ukraine, and its boards have been shipped there as part of an Australian government support package.

So the customer list is not hobbyists alone. Some of the accounts on that portal belong to defence integrators and government buyers, which is exactly the kind of population an attacker with more than criminal motives would want to phish.

(CubePilot has not attributed the intrusion to any group, and neither will I.)

Timeline and current status

Date Event
July 24 Attacker takes over cubepilot.org DNS; TLS certificates issued for all subdomains
July 24 CubePilot regains control, revokes fraudulent certificates, notifies Australian Cyber Security Centre and police
July 24 to 25 Firmware images downloaded during this window flagged as potentially tampered
Ongoing OEM services, forum, documentation portal and ERP system remain offline

CEO Philip Rowse said on LinkedIn that the ERP portal, the internal system CubePilot uses to run orders and invoicing, was also pulled offline as a precaution while the investigation runs.

The incident was first reported by BleepingComputer.

What drone operators should do right now

If you logged into any CubePilot service on July 24, change that password, and change it anywhere else you reused it. Turn on two-factor authentication where the service offers it.

Do not flash any firmware image downloaded from CubePilot on July 24 or 25 to a drone until the company confirms the file is clean. Files pulled before July 24 are considered safe.

One more warning from the company: if you get an email or message asking you to pay a CubePilot invoice, do not act on it. Ring your usual contact at the company and confirm it by voice. Payment redirection is a classic follow-on move after this kind of hijack, and the attacker has had time to read internal mail.

© 2026 Threat Vectr