Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachphishing-campaign-intelligencebreach-disclosure-notificationvoice-social-engineering

Social engineering attacks on Mailchimp exposed customer accounts and fueled phishing

Updated 28d agoFirst seen May 25, 20264 sources

Mailchimp disclosed that attackers used social engineering against employees and contractors to steal credentials and access an internal customer support and account administration tool, leading to unauthorized access to 133 customer accounts. The company said it detected the activity on January 11, suspended affected accounts, and notified impacted customers within 24 hours. Mailchimp added that passwords and payment card data were not exposed, but the compromised account information could still be used for targeted phishing and other follow-on attacks.

The incident echoed an earlier Mailchimp breach in which intruders again manipulated employees to gain access to internal tools and target customers in the cryptocurrency and finance sectors. In that earlier case, attackers compromised 319 accounts, exported audience data from 102 accounts, accessed some customer API keys that were later disabled, and used the stolen data to send phishing emails, including messages aimed at Trezor users that impersonated breach notifications. The repeated intrusions highlighted the downstream risk posed by marketing platforms that hold customer contact data and administrative access across many organizations.

Share:
Social engineering attacks on Mailchimp exposed customer accounts and fueled phishing
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jan 18, 20233y ago

Mailchimp publicly discloses January 2023 breach

Mailchimp publicly disclosed the January 2023 breach, stating that 133 customer accounts were accessed through a social-engineering attack on employees and contractors. Reporting noted the incident's similarity to the company's earlier 2022 breaches affecting cryptocurrency-related customers.

Jan 12, 20233y ago

Mailchimp suspends affected accounts and notifies impacted customers

Within 24 hours of discovering the January 2023 intrusion, Mailchimp temporarily suspended the affected accounts, notified primary contacts for all impacted customers, and sent recovery guidance. Mailchimp said no passwords or credit card data were compromised and continued investigating.

Jan 11, 20233y ago

Mailchimp detects new employee social-engineering attack affecting 133 accounts

Mailchimp detected unauthorized activity on 2023-01-11 after attackers used compromised employee and contractor credentials to access an internal customer support and account administration tool. The attacker accessed 133 customer accounts in the new breach.

Apr 5, 20224y ago

Mailchimp discloses 2022 breach impacting 319 accounts and disables exposed API keys

Mailchimp disclosed that attackers compromised 319 accounts, exported audience data from 102 customer accounts, and accessed some customer API keys, which the company later disabled. The breach was linked to phishing activity against customers including Trezor users.

Mar 26, 20224y ago

Mailchimp detects social-engineering breach affecting crypto and finance customers

Mailchimp discovered that threat actors had socially engineered employees to obtain credentials and access internal customer support and account administration tools. The intrusion targeted cryptocurrency and finance-related customers and was identified on 2022-03-26.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.