Skip to content
NetarxImpact Database
Help Desk ImpersonationNo AI reportedConfirmed

Mailchimp employees socially engineered, exposing DigitalOcean and Trezor customers

Mailchimp (Intuit) · Technology · United States · January 11, 2023

What happened

Mailchimp disclosed that attackers had socially engineered employees and contractors to obtain credentials, then used internal support and administrative tooling to view data belonging to customer accounts. The August 2022 incident affected accounts including DigitalOcean, whose customer email addresses were exposed and which subsequently dropped Mailchimp as a vendor, and hardware wallet maker Trezor, whose customer list was later used to launch a convincing phishing campaign against wallet holders.

How the deception worked

Attackers targeted Mailchimp staff and contractors with social engineering and credential phishing to obtain working logins for internal administrative tools. Those tools are designed to let support staff view and act on any tenant's account, so a single compromised employee login gave access to audience lists and API keys across many customers. The attackers focused on accounts in cryptocurrency and finance, exported subscriber lists, and in some cases obtained API keys that would allow sending mail as the customer. Trezor's stolen list was then used to send phishing mail that appeared to come from Trezor itself, directing recipients to a fake wallet application.

AI involvement · No AI reported

No AI element reported.

The control that would have caught it· our reading, not a claim from the sources

Repeat compromise of the same support console is a design problem: scope agent access to a single ticketed customer at a time and require phishing-resistant MFA plus supervisor approval for bulk views.

Sources (7)

  1. Mailchimp suffers another data breach after social engineering attack on employees
    Computing·computing.co.ukOpen ↗
  2. DigitalOcean says customer email addresses were exposed
    TechCrunch·techcrunch.comOpen ↗
  3. Impact to DigitalOcean customers resulting from Mailchimp security incident
    DigitalOcean·digitalocean.comOpen ↗
  4. Mailchimp suffers third breach in 12 months
    Computer Weekly·computerweekly.comOpen ↗
  5. IOTW: Mailchimp suffers another social engineering attack
    Cyber Security Hub·cshub.comOpen ↗
  6. Mailchimp discloses a new security breach, the second one in 6 months
    Security Affairs·securityaffairs.comOpen ↗
  7. Companies impacted by Mailchimp data breach warn their customers
    Security Affairs·securityaffairs.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.