Email Autoresponder Free

Main Menu

  • Home
  • Email accounts
  • Email marketing
  • Email newsletter
  • Email verifier

Email Autoresponder Free

Header Banner

Email Autoresponder Free

  • Home
  • Email accounts
  • Email marketing
  • Email newsletter
  • Email verifier
Email marketing
Home›Email marketing›Hackers breached email marketing company Mailchimp to launch crypto phishing scams

Hackers breached email marketing company Mailchimp to launch crypto phishing scams

By Michael E. McChristian
April 5, 2022
0
0

Email marketing service Mailchimp revealed a data breach on Monday that compromised an internal tool to gain unauthorized access to customer accounts and stage phishing attacks.

The development was first reported by Bleeping Computer.

The company, which was acquired by a financial software company Intuitive in September 2021, told the publication that she became aware of the incident on March 26 when she became aware of a malicious party accessing the customer support tool.

“The incident was propagated by an external actor who successfully carried out a social engineering attack against Mailchimp employees, which compromised employee credentials,” said Siobhan Smyth, chief security officer. information at Mailchimp.

cyber security

Although Mailchimp said it acted quickly to terminate access to the hacked employee account, the siphoned credentials were used to access 319 MailChimp accounts and further export mailing lists relating to 102 accounts.

The unidentified actor also allegedly gained access to API keys for an unspecified number of customers, which the company says have been disabled, preventing attackers from misusing API keys to mount phishing email campaigns. .

In the wake of the breach, the company also recommends customers enable two-factor authentication to secure their accounts against takeover attacks.

The acknowledgment comes as cryptocurrency holding company Trezor said on Sunday that it was investigating a potential security incident resulting from an opt-in newsletter hosted on Mailchimp after the actor repurposed stolen data to send malicious emails alleging that the company had suffered a security incident.

The scam email, which came with a supposed link to download an updated version of the Trezor suite hosted on what is actually a phishing site, tricked unsuspecting recipients into connecting their wallets and entering the seed phrase on the trojanized lookalike app, allowing the adversary to transfer the funds to a wallet under their control.

cyber security

“This attack is exceptional in its sophistication and was clearly planned to a high level of detail,” Trezor explained. “The phishing app is a cloned version of Trezor Suite with very realistic features, and also includes a web version of the app.”

“Mailchimp has confirmed that its service has been compromised by an insider targeting crypto companies,” Trezor said later. tweeted. “We managed to take the phishing field [trezor.us] offline,” warning its users to refrain from opening company emails until further notice.

The American company has not yet specified whether the attack was carried out by an “insider”. It is also unclear at this point how many other cryptocurrency platforms and financial institutions are affected by the incident.

A second confirmed victim of the breach is Decentraland, a 3D virtual world browser-based platform, which revealed on Monday that “the email addresses of its newsletter subscribers were leaked in a data breach. Mailchimp”.

Categories

  • Email accounts
  • Email marketing
  • Email newsletter

Recent Posts

  • How to start an email newsletter
  • Email Marketing and Marketing Automation: The Differences Explained
  • 4 Ways to Use Video in Your Email Marketing Campaigns
  • 5 Best ConvertKit Alternatives for Email Marketing Campaigns
  • Here’s why email marketing is (still) important in 2022

Archives

  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • September 2020
  • June 2020
  • May 2020
  • December 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • March 2018
  • January 2018
  • September 2017
  • November 2016
  • July 2016
  • October 2015
  • April 2015
  • July 2014
  • March 2014
  • June 2013
  • September 2011
  • July 2011
  • Privacy Policy
  • Terms and Conditions