Data Breaches

MailChimp discloses new breach after employees got hacked

0

Email marketing and newsletter platform MailChimp suffered a new breach in which threat actors accessed an internal customer support and account administration tool and exposed the data of 133 customers.

The attackers gained access to employee credentials after conducting a social engineering attack on Mailchimp employees and contractors.

MailChimp detected an unauthorized person accessing their support tools on January 11th. Immediately they temporarily suspended account access for Mailchimp accounts where suspicious activity was detected in order to protect the users’ data.

All affected accounts were notified on January 12 about the breach. The firm assured that no credit card or password information was compromised as a result of this incident.

The investigation process is ongoing, and includes identifying measures to further protect the platform.

One of the customers affected by this breach is the popular WooCommerce eCommerce plugin for WordPress.

WooCommerce has emailed customers warning them that the MailChimp breach exposed their names, store URLs, addresses, and email addresses.

While WooCommerce states that there is no indication that the stolen data has been misused, threat actors commonly use this type of data for targeted phishing attacks to steal credentials or install malware.

Mailchimp suffered a similar breach in April 2022, where the threat actors gained access to internal tools of the email marketing giant to conduct phishing attacks against crypto customers.

Image Credits : Anonymania

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Nissan North America data breach caused by third-party provider

Previous article

Ransomware attack hits nearly 300 fast food restaurants in UK

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *