Saturday, January 28, 2023
-Advertisement-
HomeTechSocial engineering attack exposes customer data: Mailchimp responds

Social engineering attack exposes customer data: Mailchimp responds

Published Date:

Mailchimp, a platform for mass email and marketing automation, reported that it was hacked on January 11, with malicious actors obtaining access to information from 133 accounts. The information could be used to deliver unsolicited advertisements or targeted phishing attempts to account owners.

The company stated that its security team discovered a “unauthorized actor” gaining access to one of its internal systems used by Mailchimp customer-facing teams for customer assistance and account administration. This actor had carried out a social engineering attack against Mailchimp employees, gaining access to Mailchimp accounts using employee credentials obtained as part of that attack.

Attacks using social engineering differ from traditional hacking since they do not take use of technical flaws. Instead, dishonest individuals manipulate employees’ minds into divulging private information.

The 133 accounts could be mailing lists, meaning the bad guys may have acquired the email addresses of many more clients. One of the accounts was the open source e-commerce software WooCommerce. The e-commerce behemoth informed customers in a message that Mailchimp had informed them that the breach may have revealed their names, email addresses, and store web links. Customer passwords are allegedly still secure, though.

Market and consumer data expert Statista on Monday also sent out an email to customers informing them that while no password information was stolen, name and email information had been exposed in the hack.

There is “no evidence that this intrusion compromised Intuit systems or customer data beyond these Mailchimp accounts,” according to Mailchimp. In its note, the corporation didn’t specify what kind of data was stolen in the hack. However, given that Mailchimp typically only handles the distribution of newsletters and promotional emails, it’s probable that the bad guys did not manage to get their hands on confidential account information and phone numbers.

“After we uncovered evidence of an unauthorised actor, we temporarily suspended account access for Mailchimp accounts where we noticed suspicious behaviour to protect our users’ data. “On January 12, less than 24 hours after initial discovery, we alerted the primary contacts for all compromised accounts,” the business writes in a statement about the incident.

This isn’t the first time Mailchimp’s security has been compromised. Last August, the email marketing firm was the target of a similar social engineering operation in which malicious actors stole the credentials of the company’s customer care personnel and gained access to Mailchimp’s internal tools.

ALSO READ: Facebook messenger update: New Themes, reactions and end-to-end encryption

Aradhya
Aradhyahttp://thevocalnews.com
Aaradhya is working as a Sub-Editor at The Vocal News. She enjoys writing about gadgets and automobiles because she is a tech and automotive fanatic. She has done her bachelors in Journalism and Mass communication from Makhanlal Chaturvedi Rashtriya Patrakarita Vishwavidyalaya. "I write to discover what I know."
-Advertisement-

Fresh Stories

More like this

Indian woman robbed at Madrid’s Hilton Hotel, stranded in Spain

An Indian woman Jasmeet Kaur, 49, has been stranded...

Samsung set to unveil five galaxy Book3s at unpacked event, check details

During this year's Unpacked event on February 1, South...

Masaba Gupta introduces the world to her stunning blended family with Vivian Richards and Neena Gupta

Masaba Gupta, an actor and fashion designer, wed Satyadeep...

Earth to have rare close encounter with asteroid this week

NASA Systems, an asteroid the size of a box...

“Hope for All the Women…”: Shoaib Malik reflects on Sania Mirza’s success at the Australian open

Sania Mirza, an Indian tennis player, finished second with...

Masaba Gupta and Dad Viv Richards pose at post-wedding party: Get the guest list here

On Friday, Masaba Gupta and Satyadeep Misra were wed...

Crisis in Pakistan: What happens as the rupee plummets to a record low?

Pakistan appears to be breaking apart. The government, governed...

PM to make historic visit to key Gujjar area in Rajasthan: BJP leader

On the 1111th anniversary of Bhagwan Dev Narayan's birth,...

Delhi: Ex-students from 26 states, 12 countries participate in Don Bosco School Alumni Meet

New Delhi: Around 850 former students of Don Bosco...

Pariksha Pe Charcha: Student asked, ‘Hard Work Or Smart Work’? Here’s PM Modi’s reply

New Delhi: Prime Minister Narendra Modi on Friday held...

Budget 2023: Expert explains Income Tax expectations of salaried taxpayers

By CA Yamini Gujar, Financial Advisor Taxpayers are expected to...

Will Egypt allocate special area of land to India in Suez Canal Economic Zone?

A day after Prime Minister Narendra Modi and Egyptian...

Coca-Cola phone: Specs and design revealed, check details

The Coca-Cola smartphone is anticipated to make its debut...

Enhance your mobile gaming with noise buds combat: A look at price, specs and more

Users can now set both an image and an...

Game count with Noise Buds combat gaming TWS: Price and specs

Indian tech company Noise has announced the release of...

Infinix Note 12i with 5000mAh battery and 6.7″ display for just Rs 9999, check details

The Note 12i, the most recent smartphone in the...

BharOS reality check: Are govt and private firms ready for launch?

IIT-Madras-incubated JandK Operations Pvt. Ltd., which created BharOS, India's...

How scientists discovered Earth’s inner core was spinning in opposite direction

A significant change could be happening right under our...

Indian dreams crushed with heartbreaking FIH men’s hockey WC penalty shootout loss against New Zealand

India was eliminated from the FIH Men's Hockey World...

Breaking the cycle: First time in 12 years India invites Pakistan’s FM to SCO meet

The conference of the Shanghai Cooperation Organization (SCO) foreign...