An attacker exploited PostHog EU's invite system to send phishing emails containing malicious links between April 22-24, affecting users who received unexpected invite emails. PostHog deployed a fix to prevent further abuse, blocked the attacker, and confirmed no compromise of their data or systems occurred. The incident was resolved after 12.9 hours with continued monitoring for additional malicious activity.
Trusted by 1,000+ teams
Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.
We are investigating reports of an attacker abusing PostHog's invite process to send phishing emails. The emails use our standard invite template but contain a link directing to a malicious external site. If you received an unexpected PostHog invite email between April 22–24, do not click any links in it. Fewer than 0.03% of the targeted email addresses matched records in our database, suggesting it is unlikely this list originated from a PostHog data leak. We have found no evidence of a compromise of PostHog systems and have deployed a fix to prevent similar attacks.
We've deployed a fix to prevent further abuse of our invite process following reports of phishing emails sent using it. The attacker has been blocked and we are monitoring for further activity. We have found no evidence of a compromise of PostHog data or systems. If you received an unexpected PostHog invite email between April 22–24, do not click any links in it.
With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.
Start free trialNo credit card required · Cancel anytime · 6320 services available
Integrations with