Skip to content
NetarxImpact Database
Credential Phishing PortalNo AI reportedConfirmed

Klaviyo employee phished; attacker used internal tools to take crypto mailing lists

Klaviyo · Technology · United States · August 3, 2022

What happened

Email marketing platform Klaviyo disclosed that on 3 August 2022 a threat actor phished an employee's credentials and used internal support tools to search for cryptocurrency-related customer accounts. The attacker viewed list and segment information for 44 Klaviyo customer accounts and downloaded data from 38 of them, plus two internal Klaviyo lists. The downloaded data included names, email addresses, phone numbers and custom profile properties, but no passwords or card numbers.

How the deception worked

The employee's log-in credentials were captured through a phishing attack, giving the attacker an authenticated session inside Klaviyo's internal support environment. From there the operation was pure search: the attacker queried the customer base specifically for cryptocurrency companies and pulled their subscriber lists. The objective was never Klaviyo itself but the audience data its crypto customers had entrusted to it, because a verified list of a crypto exchange's subscribers is a ready-made target set for wallet-draining phishing. Klaviyo subsequently restricted employee access to internal tooling and improved detection of anomalous internal behaviour.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant MFA on staff accounts plus alerting on unusual cross-tenant queries in support tools would have caught a search pattern this specific.

Sources (2)

  1. Klaviyo security incident
    Klaviyo·klaviyo.comOpen ↗
  2. Email marketing firm hacked to steal crypto-focused mailing lists
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.