August 2026
AirDroid recently identified and contained a phishing-related security incident involving a single employee email account. We are sharing this notice to provide transparency regarding what occurred, the scope and impact of the incident, and the actions we have taken in response.
The incident was contained, and our investigation to date has found no evidence of unauthorized access to AirDroid products, production environments, internal systems, or customer data maintained within AirDroid products.
What Happened
On August 6, 2026, we identified unauthorized access to one employee's Google Workspace mailbox.
Our investigation indicates that the employee had previously received a phishing email sent from an account associated with another organization and presented as a legitimate business communication. The message used a business-related lure and directed the employee to a phishing site.
After the employee interacted with the phishing message, an unauthorized party gained access to the employee's mailbox. The compromised mailbox was subsequently used to send phishing emails to external recipients. One of the phishing messages used the subject line:
“PROPOSAL INVITATION - PARTNERSHIP”
This incident was the result of an external phishing and credential-compromise attack. Based on our investigation, we have found no evidence that the incident resulted from a vulnerability in AirDroid products, services, core systems, or infrastructure.
Investigation Findings and Scope
Our investigation confirmed that only one employee email account was affected by this incident.
The affected mailbox was used solely for external email communications and was not connected to, or used as an authentication mechanism for, AirDroid's internal business systems, production environments, product infrastructure, or customer-facing services.
Following the employee's internal report, our Security team immediately reviewed the relevant sign-in records, account activity, authentication events, and available security logs associated with the mailbox.
Based on this review, we have identified no evidence of unauthorized access to:
- any other employee email account;
- AirDroid's internal systems or corporate infrastructure;
- AirDroid's production environments;
- AirDroid products or services; or
- customer systems or customer data maintained within AirDroid products as a result of this incident.
Recipient Notification
We reviewed available outbound mail records associated with the compromised mailbox and identified the recipient addresses associated with the unauthorized messages. We sent a security warning to those identified addresses advising recipients not to click links, open unexpected attachments, provide credentials, or otherwise interact with the suspicious emails.
Immediate Containment and Response
AirDroid team took immediate action after the incident was identified and reported internally.
Within approximately two hours of the unauthorized phishing emails being sent, access to the affected account was secured, the account password was reset, and all active sessions and account authorizations were revoked.
The AirDroid Security team then initiated an investigation to determine the scope of the incident and identify any potential additional impact. Our response included:
- resetting and securing the affected account;
- revoking existing sessions and account authorizations;
- reviewing all available sign-in and account activity logs associated with the affected mailbox;
- verifying whether the account had any access path to internal systems or other company resources;
- monitoring the account for subsequent anomalous authentication or sign-in activity;
- identifying recipients of the unauthorized phishing messages;
- notifying identified recipients of the potential phishing risk; and
- contacting the organization associated with the mailbox from which the original phishing message was received and advising them to investigate their potentially compromised account.
Following these containment measures, our monitoring has not identified further anomalous sign-in activity associated with the affected mailbox.
Additional Company-Wide Security Measures
Although the investigation determined that the incident was limited to a single employee mailbox, we have taken additional precautionary measures across the organization.
These measures include:
- conducting a company-wide review of email account authorizations and connected access permissions;
- strengthening authentication and sign-in permission reviews for employee accounts;
- reviewing account access controls and security configurations for potential unnecessary or excessive permissions;
- increasing monitoring for suspicious authentication and account activity; and
- requiring all employees to complete additional security awareness training focused on phishing, social engineering, credential theft, and suspicious login requests.
These measures are intended to further reduce the likelihood of successful social-engineering attacks and limit their potential impact should similar attempts occur in the future.
Guidance for Recipients
If you received an unexpected email from an AirDroid employee with the subject “PROPOSAL INVITATION - PARTNERSHIP”, or another similar message containing an unexpected link, attachment, or request, we recommend that you:
- do not click any links or open unexpected attachments contained in the message;
- do not enter account credentials on any website reached through the message;
- delete or quarantine the suspicious email;
- report the message to your organization's IT or Security team; and
- if you interacted with the message or entered credentials, promptly reset the affected credentials, clear your cookies and review the relevant account for suspicious activity.
Note: For Google Workspace accounts, administrators can reset sign-in cookies after a password change. For personal Gmail accounts, users should review Manage all devices and sign out of any suspicious sessions.
Recipients who have already received and followed our security notification do not need to take additional action unless contacted separately by our Security team.
Ongoing Security Review
The immediate containment, investigation, and recipient-notification actions relating to this incident have been completed.
Our investigation to date confirms that the incident was limited to one employee's Google Workspace mailbox, which was used for external communications and did not provide access to AirDroid's internal or production systems.
We will continue to monitor relevant security activity and review our controls as part of our ongoing security program.
Protecting our customers, partners, and users remains a priority for AirDroid. We appreciate the customers and security researchers who promptly reported suspicious activity and provided technical information that assisted our investigation and response.
If our continuing review identifies any material change to the scope or impact described in this notice, we will provide an appropriate update.
For security-related questions regarding this incident, please contact the AirDroid Security team through our official support or security communication channels.