CIRCL Information

Report an Incident or Vulnerability

Get help from CIRCL

Choose the right reporting process

Security incidents, suspected phishing URLs, and newly discovered vulnerabilities require different responses. Select the option that best describes your situation so it reaches the right process quickly.

Incident response

Something is happening now

Use the general incident response process for compromised systems, malware, phishing, website defacement, unauthorised access, or other active security events.

  • Contain and investigate an active incident
  • Get guidance from the CIRCL response team
  • Preserve evidence for later analysis
Report an incident

Coordinated Vulnerability Disclosure

You found a vulnerability

Use the CVD process when you discover a weakness in hardware, software, a service, or a procedure and want to coordinate its responsible disclosure and remediation.

  • Report a previously unknown security weakness
  • Coordinate with vendors and affected parties
  • Follow the dedicated disclosure policy
View the CVD process

Phishing report

You received a suspicious URL

Use LookyLoo to open and test a suspected phishing URL in an isolated browser instead of visiting it on your own device.

  • Capture the URL safely with LookyLoo
  • Review the page and its network activity
  • Use LookyLoo's report button to request automatic take-down
Test and report with LookyLoo

General incident response

Report an incident

Contact CIRCL as soon as an incident is detected or suspected. Include as much relevant detail as possible; all reported information will be treated confidentially.

See the contact page for full contact details and CIRCL's OpenPGP information.

Before and during reporting

Protect the evidence

Focus on containment while avoiding changes that could make the incident harder to investigate.

1

Contact CIRCL first

Report the event as soon as possible. CIRCL can advise you on safe emergency actions.

2

Record every action

Note who did what, when, why, the expected outcome, and the actual outcome. Always include the time zone.

3

Avoid altering systems

Where possible, disconnect a system from the network rather than turning it off. Do not install, copy, move, or delete software, files, data, or logs.

4

Contain, but do not recover yet

Avoid major changes beyond containment. Evaluate the impact on evidence before eradicating the cause or beginning recovery.

5

Share useful context

Include precise timestamps, contact details, phone numbers, and your PGP key when available.

Useful resources

Prepare your report

Our commitment

Confidentiality

CIRCL's primary goal is to help victims of information security incidents, mainly in Luxembourg, while maintaining strict confidentiality. CIRCL will not provide incident details to third parties without the reporter's prior consent, except where disclosure is required by applicable law or valid legal process.

For legal complaints, CIRCL assists Luxembourg law enforcement agencies. CIRCL's role is to respond to and coordinate information security incidents in the sole interest of information security in Luxembourg.

Top