A security breach in HotCRP allowed unauthorized parties to download approximately 500 PDF files and attachments submitted to CCS 2026 prior to the submission deadline. Impacted authors have been personally contacted on January 16th. The attackers were unable to modify any submission data and did not have access to submission metadata, including author identities, reviewer identities, or review content. The vulnerability has since been fixed, and the incident is still under investigation. Further information is available at: https://hotcrp.com/news/2026/security-notice-202601
As Program Committee Chairs, we are deeply sorry for this incident, which was beyond our control. The breach occurred before any paper assignments were made, and the review process will proceed as originally planned. A copy of the exfiltrated material has been preserved along with timestamps. If any authors believe their ideas may have been misappropriated as a result of this breach, they are encouraged to contact the Program Chairs.