Mailchimp Hacked for a Second Time in Six Months

Software

Published:

mailchimp hacked
Image Credit: Mailchimp

On January 11, the Mailchimp Security team identified an unauthorized actor who had accessed one of the company’s tools used by customer-facing teams for customer support and account administration.

Mailchimp has said that the incident impacted 133 Mailchimp accounts

The unauthorized actor conducted a social engineering attack on Mailchimp employees and contractors and obtained access to select Mailchimp accounts using employee credentials that were compromised in that attack.

According to Mailchimp, the targeted incident has been limited to 133 Mailchimp accounts, and there’s no evidence that this compromise affected Intuit systems or customer data beyond these Mailchimp accounts.

After identifying the unauthorized actor, Mailchimp temporarily suspended account access to accounts where suspicious activity was detected to protect users’ data.

Mailchimp notified the primary contacts for all affected accounts on January 12, less than 24 hours after the initial discovery. That afternoon, the company sent another email to affected accounts with steps to help users reinstate access to their Mailchimp accounts safely.

Since then, Mailchimp has been working with users directly to help them reinstate their accounts, answer questions, and provide any additional support they need.

For the Second Time in Six Months, MailChimp is Hacked

Twitter user Armin shared the email from WooCommerce, one of Mailchimp’s customers affected by the data breach. The email reads,

On January 12, 2023, we were notified about an unauthorized breach of Mailchimp, a communications tool WooCommerce uses to send emails to customers

The email went on the say,

This breach may have resulted in some of the information you’ve shared with us, including your name, store URL, address, and email address, being exposed. No payment data, passwords, or sensitive security information is part of this breach.

If this is giving you deja-vu, it’s because, basically, the same hack happened in August 2022. At that time, Mailchimp said that 214 accounts had been affected and that they had implemented additional security measures.

Mailchimp has apologized for any frustration caused by the incident and is continuing its investigation. The company will be providing impacted account holders with timely and accurate information throughout the process.

If anyone has any questions regarding a notice they received or the incident in general, they can reach out to [email protected].

Read More
Stephania Mote

Latest

Everything you need to know about Greek yogurt and how it can meet your nutrition needs

Recipes Two-ingredient cheesecake. Turkish-style pasta. Baked yogurt toast. Bagels....

Cook This: 3 recipes from Istanbul, including one of Turkey’s favourite breakfasts

Recipes Özlem Warren shines a light on the culinary...

Green Sauce Tofu and More Recipes We Made This Week

Recipes It’s no secret that Bon Appétit editors cook...

Newsletter

Don't miss

Everything you need to know about Greek yogurt and how it can meet your nutrition needs

Recipes Two-ingredient cheesecake. Turkish-style pasta. Baked yogurt toast. Bagels....

Cook This: 3 recipes from Istanbul, including one of Turkey’s favourite breakfasts

Recipes Özlem Warren shines a light on the culinary...

Green Sauce Tofu and More Recipes We Made This Week

Recipes It’s no secret that Bon Appétit editors cook...

Marshmallow Creme vs. Fluff: The Sweet and Sticky Showdown

Recipes Skip to main content Taste of Home Taste of Home Do...

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID

Business groups are fighting Labor’s CGT changes. Here is where SMEs stand

Labor’s most contested tax reform in a generation cleared its first formal hurdle on Thursday and immediately ran into organised resistance. Treasurer Jim Chalmers introduced the government’s tax reform legislation to the House of Representatives on 28 May, bundling together four budget measures: the capital gains tax overhaul, new limits on negative gearing, a $250