April 2026: Phishing emails sent via PostHog invite system
An attacker exploited PostHog EU's invite system to send phishing emails containing malicious links between April 22-24, affecting users who received unexpected invite emails. PostHog deployed a fix to prevent further abuse, blocked the attacker, and confirmed no compromise of their data or systems occurred. The incident was resolved after 12.9 hours with continued monitoring for additional malicious activity.