CSIDB logo
Incident

Mailchimp

Incident posture

Attack window
Aug 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-17 00:00

Linked entities

Victim
Mailchimp
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity incident at Mailchimp involved unauthorized access to an internal customer support tool via a social engineering attack that compromised employee credentials. The company temporarily suspended accounts exhibiting suspicious activity, primarily affecting 214 users in cryptocurrency and finance sectors, and notified impacted customers while implementing enhanced security measures. The breach was part of a broader trend targeting crypto-related entities, prompting proactive account protections and follow-up guidance to restore secure access for affected users.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

4 techniques

Description

On August 8, 2022, Mailchimp’s Security team identified unauthorized access to an internal tool utilized by customer-facing teams for support and account administration. The breach originated from a social engineering attack targeting Mailchimp employees, through which the attacker obtained compromised credentials. Mailchimp characterized the incident as part of a broader trend of sophisticated phishing and social engineering campaigns directed at cryptocurrency-related organizations. In response, the company temporarily suspended account access for users exhibiting suspicious activity, emphasizing this was not an industry-wide suspension but a targeted measure to protect data. Notifications were sent to primary contacts of impacted accounts on August 10, alongside the implementation of enhanced security protocols. Mailchimp reaffirmed its commitment to serving crypto clients and initiated a review of its Standard Terms of Use and Acceptable Use Policy to align with crypto industry support.

The investigation confirmed 214 Mailchimp accounts were compromised, primarily affecting users in cryptocurrency and finance sectors. On August 22, Mailchimp contacted affected account owners with instructions to safely restore access. The company acknowledged the incident caused operational disruptions and user uncertainty, issuing an apology while maintaining ongoing communication with impacted parties. No additional account suspensions based on industry classification occurred, and Mailchimp continued its investigation without disclosing further technical specifics regarding attacker methodologies beyond the initial social engineering vector. The incident underscored targeted risks to crypto-related entities but did not prompt systemic policy changes beyond the stated security enhancements and policy reviews.

Sources

Sources available to members: 1 source.

CSIDB