@vectorpunks@posthog Thanks for flagging. It looks like a user is sending invites from their Posthog account that contains a URL in the Org name. Not a hack, but something we do need to look at to prevent bad actors
@BenLeaPH@posthog How was my email address leaked to them??
Granted this is not the only phishing email I get but it seems too much of a coincidence that I’ll start getting phishing emails from posthog right after I signed up. I haven’t created any orgs or really used the account.
@vectorpunks@BenLeaPH@posthog Of all the emails that this attacker sent, only 0.04% had existing PostHog accounts and there are no other signs of a breach, so I can confirm that your email address being hit here was a coincidence
we're working on fixing the abuse path. sorry!