Email marketing giant Mailchimp has suffered a data breach as a result of a “sophisticated” cyber-attack which saw data stolen from more than 100 customers.
In a statement on Monday 4th April, Mailchimp confirmed the incident, revealing that hackers used internal tools to steal user data and launch secondary attacks against customers in the cryptocurrency and finance space.
Mailchimp’s response to the cyberattack is still ongoing, but here’s what we know so far.
Grumblings Online
Last week, users of the Trezor crypto wallet began reporting they had been targeted by phishing emails. And on Sunday the firm issued a statement on social media confirming that the phishing attempts were a result of an apparent breach at Mailchimp.
In a blog post, the crypto firm said: “The Mailchimp security team disclosed that a malicious actor accessed an internal tool used by customer-facing teams. The bad actor gained access to this tool as a result of a successful social engineering attack on Mailchimp employees.”
Trezor described the phishing attacks as “exceptional” and “clearly planned to a high level” of detail. The phishing emails directed users to a highly sophisticated, cloned version of the Trezor Suite app, according to the firm’s security team.
Mailchimp’s response
Speaking to The Verge, Mailchimp CISO Siobhan Smyth said the firm first became aware of the incident on 26th March when security personnel detected unauthorised access to a tool used by customer support and administration teams.
The company reacted swiftly, deactivating compromised accounts upon learning of the breach.
However, despite Mailchimp’s rapid response, hackers were able to view around 300 user accounts and steal audience data belonging to 102 clients.
“We sincerely apologize to our users for this incident and realize that it brings inconvenience and raises questions for our users and their customers,” Smyth told The Verge.
“We take pride in our security culture, infrastructure, and the trust our customers place in us to safeguard their data. We’re confident in the security measures and robust processes we have in place to protect our users’ data and prevent future incidents.”
Recommended
- Leader Insights | The importance of data-centric recruitment
- New UK regulations to push adoption of stablecoins
- Photonics design centre opens at Strathclyde Uni
Who has been affected by the Mailchimp data breach?
With data belonging to 102 Mailchimp clients exposed in the breach, it’s possible that customers of several organisations could be impacted. However, at present Trezor appears to be the only organisation seriously affected.
Metaverse platform Decentraland revealed its newsletter was also among those exposed, so it is likely that other organisations will begin revealing how the fallout has affected them in the coming days.
In a statement, Mailchimp said that owners of compromised accounts have been informed, and the organisation is working closely with affected parties.
Similarly, Trezor warned customers to remain vigilant of potential phishing scams in the wake of the incident, and advised users to report any suspicious activity or attempted attacks to the company’s security division.
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





