{"id":476999,"date":"2023-01-19T12:08:46","date_gmt":"2023-01-19T10:08:46","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=476999"},"modified":"2023-01-19T12:10:23","modified_gmt":"2023-01-19T10:10:23","slug":"mailchimp-hacked-for-second-time-in-a-year","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/476999-mailchimp-hacked-for-second-time-in-a-year.html","title":{"rendered":"Mailchimp hacked for second time in a year"},"content":{"rendered":"<p>Email marketing company Mailchimp <a href=\"https:\/\/mailchimp.com\/january-2023-security-incident\/?=7194ef805fa2d04b0f7e8c9521f97343\" target=\"_blank\" rel=\"noopener\"><strong>has confirmed<\/strong><\/a> it suffered a second hacking incident in less than a year.<\/p>\n<p>Mailchimp&#8217;s security team identified an unauthorised actor accessing one of the tools used by the company&#8217;s customer-facing teams for customer support and account administration on 11 January 2023.<\/p>\n<p>Its investigations found that the unauthorised actor conducted a social engineering attack on Mailchimp employees and contractors.<\/p>\n<p>These types of attacks use manipulation via phone calls, texts, or emails to convince a target that they must share details that could lead to sensitive accounts or systems being accessed.<\/p>\n<p>Two of the most high-profile cases where this technique was used were the 2022 hackings of Uber and Rockstar Games, both of which were supposedly carried out by a 17-year-old teenager from the UK.<\/p>\n<p>An intruder previously accessed 214 Mailchimp accounts through a social engineering attack in March 2022. The company only acknowledged the incident in August 2022.<\/p>\n<h2 class=\"my-4\">133 more accounts exposed in latest breach<\/h2>\n<p>In the latest attack, the hackers obtained access to &#8220;select&#8221; Mailchimp accounts using employee credentials compromised through the same technique.<\/p>\n<p>&#8220;Based on our investigation to date, this targeted incident has been limited to 133 Mailchimp accounts,&#8221; the company said.<\/p>\n<p>Mailchimp stated there was &#8220;no evidence&#8221; that the breach had affected the systems of its parent company Intuit or customer data beyond the Mailchimp accounts compromised.<\/p>\n<p>It temporarily suspended account access for the affected accounts where suspicious activity was detected to protect users&#8217; data.<\/p>\n<p>&#8220;We notified the primary contacts for all affected accounts on 12 January, less than 24 hours after the initial discovery,&#8221; Mailchimp said.<\/p>\n<p>&#8220;That afternoon, we sent another email to affected accounts with steps to help users reinstate access to their Mailchimp accounts safely.&#8221;<\/p>\n<p>&#8220;Since then, we&#8217;ve been working with our users directly to help them reinstate their accounts, answer questions, and provide any additional support they need.&#8221;<\/p>\n<p><a href=\"https:\/\/techcrunch.com\/2023\/01\/18\/mailchimp-hacked\/\" target=\"_blank\" rel=\"noopener\"><strong>TechCrunch reported<\/strong><\/a> that one compromised customer was WooCommerce, which provides open-source e-commerce tools for small businesses. It has over 5 million customers.<\/p>\n<p>Mailchimp admitted that an incident of this nature could cause uncertainty and said it was &#8220;deeply sorry for any frustration.&#8221;<\/p>\n<p>&#8220;We are continuing our investigation and will be providing impacted account holders with timely and accurate information throughout the process.&#8221;<\/p>\n<hr \/>\n<h2 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/476747-lawyers-must-pay-r5-5-million-after-cyberattackers-steal-homebuyers-money.html\" rel=\"bookmark\">Lawyers must pay R5.5 million after cyberattackers steal homebuyer&#8217;s money<\/a><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>Mailchimp&#8217;s security team identified an unauthorised actor accessing one of the tools used by the company&#8217;s customer-facing teams for customer support and account administration on 11 January 2023.<\/p>\n","protected":false},"author":341042,"featured_media":477003,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[72252,71426,83791,30534],"class_list":["post-476999","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cyberattacks","tag-mailchimp","tag-social-engineering","tag-woocommerce"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/476999"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341042"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=476999"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/476999\/revisions"}],"predecessor-version":[{"id":477039,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/476999\/revisions\/477039"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/477003"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=476999"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=476999"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=476999"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}