{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-klaviyo-employee-phished-attacker-used-internal-tools-to-take-crypto-mai"},"incident":{"slug":"2022-klaviyo-employee-phished-attacker-used-internal-tools-to-take-crypto-mai","title":"Klaviyo employee phished; attacker used internal tools to take crypto mailing lists","date":"2022-08-03","date_precision":"day","year":2022,"victim_org":"Klaviyo","sector":"Technology","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Email marketing platform Klaviyo disclosed that on 3 August 2022 a threat actor phished an employee's credentials and used internal support tools to search for cryptocurrency-related customer accounts. The attacker viewed list and segment information for 44 Klaviyo customer accounts and downloaded data from 38 of them, plus two internal Klaviyo lists. The downloaded data included names, email addresses, phone numbers and custom profile properties, but no passwords or card numbers.","how_it_worked":"The employee's log-in credentials were captured through a phishing attack, giving the attacker an authenticated session inside Klaviyo's internal support environment. From there the operation was pure search: the attacker queried the customer base specifically for cryptocurrency companies and pulled their subscriber lists. The objective was never Klaviyo itself but the audience data its crypto customers had entrusted to it, because a verified list of a crypto exchange's subscribers is a ready-made target set for wallet-draining phishing. Klaviyo subsequently restricted employee access to internal tooling and improved detection of anomalous internal behaviour.","lessons":"Phishing-resistant MFA on staff accounts plus alerting on unusual cross-tenant queries in support tools would have caught a search pattern this specific.","confidence":"Confirmed","sources":[{"title":"Klaviyo security incident","url":"https://www.klaviyo.com/blog/august-2022-security-incident","publisher":"Klaviyo"},{"title":"Email marketing firm hacked to steal crypto-focused mailing lists","url":"https://www.bleepingcomputer.com/news/security/email-marketing-firm-hacked-to-steal-crypto-focused-mailing-lists/","publisher":"BleepingComputer"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-klaviyo-employee-phished-attacker-used-internal-tools-to-take-crypto-mai"}}