What happened
Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.
How the deception worked
Attackers targeted Mailchimp staff and contractors with social engineering and credential phishing to obtain working logins for internal administrative tools. Those tools are designed to let support staff view and act on any tenant's account, so a single compromised employee login gave access to audience lists and API keys across many customers. The attackers focused on accounts in cryptocurrency and finance, exported subscriber lists, and in some cases obtained API keys that would allow sending mail as the customer. Trezor's stolen list was then used to send phishing mail that appeared to come from Trezor itself, directing recipients to a fake wallet application.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
Repeat compromise of the same support console is a design problem: scope agent access to a single ticketed customer at a time and require phishing-resistant MFA plus supervisor approval for bulk views.
Sources (7)
- Mailchimp suffers another data breach after social engineering attack on employeesComputing·computing.co.ukOpen ↗
- DigitalOcean says customer email addresses were exposedTechCrunch·techcrunch.comOpen ↗
- Impact to DigitalOcean customers resulting from Mailchimp security incidentDigitalOcean·digitalocean.comOpen ↗
- Mailchimp suffers third breach in 12 monthsComputer Weekly·computerweekly.comOpen ↗
- IOTW: Mailchimp suffers another social engineering attackCyber Security Hub·cshub.comOpen ↗
- Mailchimp discloses a new security breach, the second one in 6 monthsSecurity Affairs·securityaffairs.comOpen ↗
- Companies impacted by Mailchimp data breach warn their customersSecurity Affairs·securityaffairs.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.