Security at Lifted Holdings

We build and operate payment, point-of-sale, vending and signage systems. This page is where we publish what we find, and how to reach us if you find something.

Report a security issue

Email will@liftedholdings.com. We aim to acknowledge within one business day. Machine-readable contact details are published at /.well-known/security.txt, and our handling commitments are in the vulnerability disclosure policy.

We do not operate a paid bug bounty. We do credit reporters who want credit, and we will not pursue legal action against good-faith research conducted within the policy.

Advisories

Findings from our own investigations, published with full indicators so other defenders can act on them. See all advisories.

LH-2026-001 · 2026-08-06
Credential-phishing campaign distributed from a compromised AirDroid (Sand Studio) mailbox

A two-stage adversary-in-the-middle phishing kit delivered by mail that passed SPF, DKIM and DMARC from a vendor's own domain. Includes full indicators, the disclosure timeline, and an explicit statement of what the evidence does not establish.

How we handle incidents

Three commitments that govern everything on this page:

Our own posture

Lifted Holdings operates in payments. Card data handling is scoped to validated service providers and gateway-hosted fields; we publish no claim about a certification we do not hold. Questions from customers, partners and underwriters about our controls should go to will@liftedholdings.com.