Mailchimp disclosed that attackers used social engineering against employees and contractors to steal credentials and access an internal customer support and account administration tool, leading to unauthorized access to 133 customer accounts. The company said it detected the activity on January 11, suspended affected accounts, and notified impacted customers within 24 hours. Mailchimp added that passwords and payment card data were not exposed, but the compromised account information could still be used for targeted phishing and other follow-on attacks.
The incident echoed an earlier Mailchimp breach in which intruders again manipulated employees to gain access to internal tools and target customers in the cryptocurrency and finance sectors. In that earlier case, attackers compromised 319 accounts, exported audience data from 102 accounts, accessed some customer API keys that were later disabled, and used the stolen data to send phishing emails, including messages aimed at Trezor users that impersonated breach notifications. The repeated intrusions highlighted the downstream risk posed by marketing platforms that hold customer contact data and administrative access across many organizations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Mailchimp publicly disclosed the January 2023 breach, stating that 133 customer accounts were accessed through a social-engineering attack on employees and contractors. Reporting noted the incident's similarity to the company's earlier 2022 breaches affecting cryptocurrency-related customers.
Within 24 hours of discovering the January 2023 intrusion, Mailchimp temporarily suspended the affected accounts, notified primary contacts for all impacted customers, and sent recovery guidance. Mailchimp said no passwords or credit card data were compromised and continued investigating.
Mailchimp detected unauthorized activity on 2023-01-11 after attackers used compromised employee and contractor credentials to access an internal customer support and account administration tool. The attacker accessed 133 customer accounts in the new breach.
Mailchimp disclosed that attackers compromised 319 accounts, exported audience data from 102 customer accounts, and accessed some customer API keys, which the company later disabled. The breach was linked to phishing activity against customers including Trezor users.
Mailchimp discovered that threat actors had socially engineered employees to obtain credentials and access internal customer support and account administration tools. The intrusion targeted cryptocurrency and finance-related customers and was identified on 2022-03-26.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcetherecord.media
Open sourcetechcrunch.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.