{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor"},"incident":{"title":"Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers","date":"2023-01-11","date_precision":"day","victim_org":"Mailchimp (Intuit)","sector":"Technology","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Credential Phishing Portal","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No aggregate loss figure published; downstream Trezor customers were subsequently targeted by wallet-draining phishing.","records_affected":null,"threat_actor":null,"summary":"Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.","how_it_worked":"Attackers targeted Mailchimp staff and contractors with social engineering and credential phishing to obtain working logins for internal administrative tools. Those tools are designed to let support staff view and act on any tenant's account, so a single compromised employee login gave access to audience lists and API keys across many customers. The attackers focused on accounts in cryptocurrency and finance, exported subscriber lists, and in some cases obtained API keys that would allow sending mail as the customer. Trezor's stolen list was then used to send phishing mail that appeared to come from Trezor itself, directing recipients to a fake wallet application.","lessons":"Repeat compromise of the same support console is a design problem: scope agent access to a single ticketed customer at a time and require phishing-resistant MFA plus supervisor approval for bulk views.","confidence":"Confirmed","sources":[{"title":"Mailchimp suffers another data breach after social engineering attack on employees","url":"https://www.computing.co.uk/news/4063093/mailchimp-suffers-breach-social-engineering-attack-employees","publisher":"Computing"},{"title":"DigitalOcean says customer email addresses were exposed","url":"https://techcrunch.com/2022/08/16/digitalocean-emails-mailchimp-breach/","publisher":"TechCrunch"},{"title":"Impact to DigitalOcean customers resulting from Mailchimp security incident","url":"https://www.digitalocean.com/blog/digitalocean-response-to-mailchimp-security-incident","publisher":"DigitalOcean"},{"title":"Mailchimp suffers third breach in 12 months","url":"https://www.computerweekly.com/news/252529368/Mailchimp-suffers-third-breach-in-12-months","publisher":"Computer Weekly"},{"title":"IOTW: Mailchimp suffers another social engineering attack","url":"https://www.cshub.com/attacks/news/iotw-mailchimp-suffers-another-social-engineering-attack","publisher":"Cyber Security Hub"},{"title":"Mailchimp discloses a new security breach, the second one in 6 months","url":"https://securityaffairs.com/140997/data-breach/mailchimp-security-breach.html","publisher":"Security Affairs"},{"title":"Companies impacted by Mailchimp data breach warn their customers","url":"https://securityaffairs.com/141203/data-breach/companies-impacted-by-mailchimp-breach.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor","year":2023,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-mailchimp-employees-socially-engineered-exposing-digitalocean-and-trezor"}}