- Home
- News
- Phishing emails - Please be vigilant
Phishing emails - Please be vigilant
23 March 2026
(Last updated: 21 Apr 2026 12:59)
We want to provide an update on the recent phishing emails sent to some ADI contacts. These messages have been impersonating ADI in an attempt to solicit responses and payment from recipients, specifically purchasing voouchers via Recharge. While this activity has been disruptive, we want to reassure you that no sensitive or financial information has been accessed, and we have taken extensive steps to strengthen our systems and limit any further impact.
What has happened
Late last year, several rounds of phishing emails were sent to ADI contacts using various external addresses. After a period of inactivity, a new round was sent to contacts again this week. These were sent to the same contact list originally accessed in October and delivered in small batches using different sender addresses.
What data was involved
Our developers identified an unauthorised login to the ADI website last October using an account that did not belong to any ADI user. The intruder accessed a list containing names and email addresses. No payment details or other sensitive information were stored in the system or accessed during the incident.
We want to reassure you of the following:
- No passwords, payment information, or sensitive personal data were accessed.
- The website does not store any financial details.
- The intruder could not access any member login credentials.
What we have done
A number of steps were immediately taken to further strengthen security and ensure our systems remain protected:
- Enhanced access controls - All administrator accounts now use enforced multi‑factor authentication, with passwords reviewed and access permissions checked.
- Technical security checks - The website and relevant staff systems have undergone vulnerability scanning, antivirus checks, and with additional protections for early alerting.
- Strengthened email protections - Email authentication standards have been fully reviewed to reduce the risk of impersonation, alongside increased monitoring of suspicious activity.
- Ongoing reporting and response – We immediately alerted the Information Commissioner’s Office to the incident, and we continue to report malicious domains and sender accounts to hosting providers, Action Fraud and the NCSC
These steps mean the system is now more secure and more closely monitored than ever, and we remain vigilant to any new activity.
What you can do
Please continue to treat unexpected emails with caution—especially anything requesting personal details or payment. If you receive a suspicious message, forward it to [email protected] so our team can review it immediately. Please also continue to block the sender's address, to reduce the likelihood of receiving future phishing emails.
Reassurance
We understand how frustrating these phishing attempts have been, and we share that frustration. However, we want to reiterate:
- No sensitive or financial information was accessed
- The activity has been contained to names and email addresses only
- All systems have been comprehensively reviewed.
- We are continuing to monitor and respond to any new attempts
- We will keep you informed of any further developments.
Thank you for your understanding and continued vigilance.
View other News