MVSEP (music and voice separation service) breached 4 to 6 October: a cookie-handling flaw gave the attacker command execution, then admin logins to other servers; accounts, bcrypt password hashes, plaintext API keys, uploads and support tickets treated as exposed
MVSEP, an online service that separates music and voice tracks, published a security incident notice (last updated 6 October 2026) saying an attacker was in its servers between 4 and 6 October and could read its database and stored files. Automated probing began on 4 October; at about 01:30 UTC on 5 October the attacker abused a flaw in how the website read one of its browser cookies to run commands on the web server, found login details for MVSEP's other servers and signed in to them as an administrator. The 5 October database outage was the attacker restarting the database. MVSEP fixed the flaw on all servers at 03:25 UTC on 6 October, removed the access, moved servers to key-only logins and replaced its encryption key, database and payment-provider keys, and Google, GitHub, Google Drive and Yandex Disk credentials. It is treating everything as exposed: names, email addresses, sign-in method, plan and credit balance; passwords as salted bcrypt hashes; API keys, which were stored as-is and work until replaced; processing history including file names, transcriptions, job IP addresses and webhook URLs; audio uploads still on the servers; payment records (card details are entered on Paddle and YooKassa pages and never reached MVSEP); support tickets; and cloud-storage tokens, now revoked. All saved logins were signed out. MVSEP has not said how many users are affected. Primary: MVSEP incident notice.
- Product
- MVSEP web service (mvsep.com) and back-end servers
- Versions
- n/a — incident
- Exploited in Australia?
- unknown
- Patch to
- MVSEP users: create a new API key now (old keys keep working until replaced), change your MVSEP password and the same password anywhere else you reused it, check webhook endpoints for unexpected calls, and expect phishing that quotes your uploads or plan. Site operators: a cookie-parsing flaw led to full compromise because server credentials were reachable from the web host; keep them off it and use key-only SSH.
Primary: MVSEP — Security incident: 4–6 October 2026 (last updated 6 Oct 2026)
