What happened
In 2011 email marketing provider Epsilon disclosed a breach that exposed customer names and email addresses for dozens of major bank and retail clients. A US indictment unsealed in March 2015 charged three men with breaching Epsilon and other email service providers and stealing more than one billion email addresses, which were then monetised through spam campaigns for counterfeit software that generated over $2 million.
How the deception worked
The lead defendant sent targeted phishing emails to employees of email service providers. The messages carried links to sites built to exploit browser vulnerabilities and silently install malware, giving backdoor access to employee workstations and, from there, harvested access credentials for the marketing platforms. With those credentials he bulk-downloaded subscriber lists to a server he controlled in the Netherlands. Because the stolen records paired real names with the specific brands each person banked or shopped with, they were unusually valuable for follow-on spear phishing against consumers.
AI involvement · No AI reported
No AI involvement reported.
The control that would have caught it· our reading, not a claim from the sources
Marketing platforms holding client subscriber lists need bulk-export alerting and least-privilege segregation, so one phished employee workstation cannot pull the entire customer database.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.