Skip to content
NetarxImpact Database
Spear Phishing (Email)No AI reportedConfirmed

Epsilon email marketing breach exposes address lists of banks and retailers

Epsilon Data Management and other email service providers · Professional Services · United States · April 2011

Criminal proceeds
$2,000,000
What the attackers earned. Not the same as what the victims lost, and often much smaller.
The indictment alleged the defendants generated over $2 million from spam campaigns promoting counterfeit software using the stolen lists; downstream costs to the affected brands were not quantified.
People or records affected
1,000,000,000
1.0B as reported

What happened

In 2011 email marketing provider Epsilon disclosed a breach that exposed customer names and email addresses for dozens of major bank and retail clients. A US indictment unsealed in March 2015 charged three men with breaching Epsilon and other email service providers and stealing more than one billion email addresses, which were then monetised through spam campaigns for counterfeit software that generated over $2 million.

How the deception worked

The lead defendant sent targeted phishing emails to employees of email service providers. The messages carried links to sites built to exploit browser vulnerabilities and silently install malware, giving backdoor access to employee workstations and, from there, harvested access credentials for the marketing platforms. With those credentials he bulk-downloaded subscriber lists to a server he controlled in the Netherlands. Because the stolen records paired real names with the specific brands each person banked or shopped with, they were unusually valuable for follow-on spear phishing against consumers.

AI involvement · No AI reported

No AI involvement reported.

The control that would have caught it· our reading, not a claim from the sources

Marketing platforms holding client subscriber lists need bulk-export alerting and least-privilege segregation, so one phished employee workstation cannot pull the entire customer database.

Sources (1)

  1. Feds Indict Three in 2011 Epsilon Hack
    Krebs on Security·krebsonsecurity.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.