
Sucuri account login moves to sso.sucuri.net on August 10
Sucuri is moving customer logins to a new sign-in page at sso.sucuri.net from August 10, 2026, with passwords and two-factor authentication unchanged.
Sucuri account login is moving to a new address. In a post dated August 7, 2026, Sucuri says it will begin moving customer account logins to a new authentication platform from August 10, 2026, and for most people the only visible difference will be the web address used to sign in. The new address is sso.sucuri.net, which replaces the current login page at dashboard.sucuri.net/login. Sucuri describes the move as a stronger, more modern sign-in experience, and presents it as an upgrade of the system behind the login rather than a change to how customer accounts work.
According to the announcement, customers do not have to do anything. The switch applies to all users, requires no opt-in, and does not involve updating an account or modifying any settings. Existing bookmarks to the Sucuri dashboard login page, and entries stored in a password manager (a program that remembers your logins and fills them in for you), can still be used, because the old address will automatically redirect visitors to the new authentication page. Sucuri notes that you may update a bookmark to the new address if you prefer, but that doing so is not required.
The rollout is deliberately gradual. It starts on August 10, 2026 and continues over the following few weeks, so accounts will not all transition at the same moment. Sucuri states plainly that if your account is still using the existing login page after August 10, that does not mean anything is wrong, because the account will move as the rollout progresses. The migration is designed to happen without downtime, so the Sucuri dashboard can be used normally throughout the transition.
Passwords are unaffected. Sucuri says the existing password will continue to work and that this authentication upgrade does not require a forced password reset, so customers keep signing in with the same credentials they use today. The company repeats its usual advice: use a password that is unique to the Sucuri account rather than reusing one from another service, and reset or refresh it regularly as a standard security practice.
Two-factor authentication, often shortened to 2FA (a second proof of identity, such as a code from an app or a text message, entered in addition to the password), also stays as it is. Sucuri says existing 2FA configurations will continue working as they do today. There is no need to enroll in 2FA again, change the current authentication method, reconfigure the account, or generate a new setup as part of the migration. The company's point is that the upgrade changes the platform behind the login process, not the customer's 2FA arrangement.
The same applies to organisations that sign in through a central system. Sucuri says customers already using SSO (single sign-on, where one login handled by a company system unlocks several services) or SAML integrations should not need to make any changes. Existing integrations will continue working as before and are not expected to be interrupted, so teams that manage access to Sucuri through an identity provider keep their established authentication workflow while the platform underneath is upgraded.
Sucuri explains the change as a matter of protecting access. In its words, protecting a website also means protecting the systems used to manage it, and account authentication matters because a website security dashboard can hold sensitive configuration, monitoring and administrative functions. The new platform is intended to give the company a more resilient and modern authentication foundation while keeping the login process familiar. Sucuri also says the upgrade is designed to improve the account recovery experience, with the updated interface intended to make recovery more straightforward for anyone who cannot get in.
Most customers will not need to take any action during the migration. If a login problem does appear, Sucuri advises first confirming that you are signing in through the official Sucuri.net login flow rather than following a link in an old or unfamiliar email or message. That is sensible advice well beyond this change: a lookalike login page is a common phishing trick used to collect passwords, and typing a known address yourself or using your own saved bookmark avoids most of the risk. If access still fails, Sucuri says to contact its support team by visiting Sucuri.net and using the live chat icon in the lower-right corner, or through the support portal.
The same page on Sucuri's site also carries the company's other recent security material, which belongs to Sucuri and its analysts rather than to us. That material includes a note by Sucuri analyst Dennis Sinegubko about a hybrid method of stealing payment card data from online shops, in which code running in the shopper's browser passes stolen details to scripts planted on the same server as the store, and mention of cross-site scripting flaws in WordPress plugins, including the YITH WooCommerce Ajax Product Filter plugin, which Sucuri says has about 100,000 users and a fix in version 3.11.1, alongside Elementor Page Builder, Careerfy, JobSearch and Newspaper. A fuller list of patched vulnerabilities is credited to John Castro at the Sucuri Labs blog.
For website owners and IT teams, the practical lesson is simple: know which address you sign in through, and treat the account that controls your site as carefully as the site itself. For our own customers, that account is the one for AEU Panel, the control panel behind AEU Hosting's managed WordPress plans, and it is worth bookmarking its real address and checking it before you type a password.
How to Protect Yourself
- Type sso.sucuri.net into your browser yourself, or use your own saved bookmark, instead of clicking a sign-in link in an email or message, even if the message looks official.
- Keep your current Sucuri password, because there is no need to change it for this move, but make sure it is a password you do not use on any other website.
- Leave your two-factor authentication (the extra code you enter after your password) exactly as it is, nothing needs to be set up again.
- After August 10, 2026, glance at the address bar before typing your password and make sure it shows sso.sucuri.net.
- If you cannot get into your account, go to Sucuri.net and use the live chat icon in the bottom-right corner rather than answering an email about your login.
- Update the bookmark in your browser to the new address when it is convenient, so you always land on the real sign-in page.
Terms Explained
- authentication the process a website uses to check that you really are who you say you are when you sign in.
- two-factor authentication an extra check, such as a code from an app or a text message, that you enter on top of your password.
- SSO short for single sign-on, one login managed by your organisation that gets you into several different services without separate passwords.
- SAML a common technical standard that lets one system confirm a person's identity to another system, so a single login can be trusted elsewhere.
- password manager a program that stores your usernames and passwords and fills them in for you.
- redirect an automatic forwarding from one web address to another.
- identity provider a central system that holds a company's user accounts and confirms who an employee is when they sign in.
- phishing a fake message or a copy of a login page that tries to trick you into typing your password.