Get help from CIRCL
Choose the right reporting process
Security incidents, suspected phishing URLs, and newly discovered vulnerabilities require different responses. Select the option that best describes your situation so it reaches the right process quickly.
01
Incident response
Something is happening now
Use the general incident response process for compromised systems, malware, phishing, website defacement, unauthorised access, or other active security events.
- Contain and investigate an active incident
- Get guidance from the CIRCL response team
- Preserve evidence for later analysis
Report an incident
02
Coordinated Vulnerability Disclosure
You found a vulnerability
Use the CVD process when you discover a weakness in hardware, software, a service, or a procedure and want to coordinate its responsible disclosure and remediation.
- Report a previously unknown security weakness
- Coordinate with vendors and affected parties
- Follow the dedicated disclosure policy
View the CVD process ↗
03
Phishing report
You received a suspicious URL
Use LookyLoo to open and test a suspected phishing URL in an isolated browser instead of visiting it on your own device.
- Capture the URL safely with LookyLoo
- Review the page and its network activity
- Use LookyLoo's report button to request automatic take-down
Test and report with LookyLoo ↗
General incident response
Report an incident
Contact CIRCL as soon as an incident is detected or suspected. Include as much relevant detail as possible; all reported information will be treated confidentially.
See the contact page for full contact details and CIRCL's OpenPGP information.
Before and during reporting
Protect the evidence
Focus on containment while avoiding changes that could make the incident harder to investigate.
1Contact CIRCL first
Report the event as soon as possible. CIRCL can advise you on safe emergency actions.
2Record every action
Note who did what, when, why, the expected outcome, and the actual outcome. Always include the time zone.
3Avoid altering systems
Where possible, disconnect a system from the network rather than turning it off. Do not install, copy, move, or delete software, files, data, or logs.
4Contain, but do not recover yet
Avoid major changes beyond containment. Evaluate the impact on evidence before eradicating the cause or beginning recovery.
5Share useful context
Include precise timestamps, contact details, phone numbers, and your PGP key when available.
Useful resources
Prepare your report
Our commitment
Confidentiality
CIRCL's primary goal is to help victims of information security incidents, mainly in Luxembourg, while maintaining strict confidentiality. CIRCL will not provide incident details to third parties without the reporter's prior consent, except where disclosure is required by applicable law or valid legal process.
For legal complaints, CIRCL assists Luxembourg law enforcement agencies. CIRCL's role is to respond to and coordinate information security incidents in the sole interest of information security in Luxembourg.