{"id":127212,"date":"2023-01-27T07:45:29","date_gmt":"2023-01-27T12:45:29","guid":{"rendered":"https:\/\/rbach.net\/?p=127212"},"modified":"2023-01-27T13:53:13","modified_gmt":"2023-01-27T18:53:13","slug":"what-you-need-to-know-about-mailchimp-security","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/what-you-need-to-know-about-mailchimp-security\/","title":{"rendered":"What You Need to Know About MailChimp Security"},"content":{"rendered":"\r\n<p><a href=\"https:\/\/mailchimp.com\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-127237\" title=\"What You Need to Know About MailChimp Security\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/logo_mailchimp-e1674762725436-134x150.png?resize=80%2C90&#038;ssl=1\" alt=\"What You Need to Know About MailChimp Security\" width=\"80\" height=\"90\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/logo_mailchimp-e1674762725436.png?resize=134%2C150&amp;ssl=1 134w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/logo_mailchimp-e1674762725436.png?resize=67%2C75&amp;ssl=1 67w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/logo_mailchimp-e1674762725436.png?w=178&amp;ssl=1 178w\" sizes=\"auto, (max-width: 80px) 100vw, 80px\" \/><\/a>Just in time for <a title=\"Data Privacy Day,\" href=\"https:\/\/iapp.org\/connect\/data-privacy-day\/\" target=\"_blank\" rel=\"nofollow noopener\">Data Privacy Day<\/a>. <strong><a title=\"Mailchimp\" href=\"https:\/\/mailchimp.com\/\" target=\"_blank\" rel=\"noopener\">Mailchimp<\/a><\/strong>, one of the largest <strong>email service-providers<\/strong> worldwide with <a title=\"Intuit to Acquire Mailchimp\" href=\"https:\/\/www.businesswire.com\/news\/home\/20210913005806\/en\/Intuit-to-Acquire-Mailchimp\" target=\"_blank\" rel=\"nofollow noopener\">13 million active customers<\/a>. suffered a <strong><a title=\"Information About a Recent Mailchimp Security Incident\" href=\"https:\/\/mailchimp.com\/january-2023-security-incident\/\" target=\"_blank\" rel=\"nofollow noopener\">security breach<\/a><\/strong>. On January 11, 2023 the Mailchimp security team reported that an unauthorized actor download the data of 133 customers of the Mailchimp service.<\/p>\r\n<h3>Mailchimp data leak<\/h3>\r\n<p><a href=\"https:\/\/iapp.org\/connect\/data-privacy-day\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-127236\" title=\"Data privacy day\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_privacy_day-2-e1674762101800-150x135.jpg?resize=90%2C81&#038;ssl=1\" alt=\"Data privacy day\" width=\"90\" height=\"81\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_privacy_day-2-e1674762101800.jpg?resize=150%2C135&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_privacy_day-2-e1674762101800.jpg?resize=75%2C67&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_privacy_day-2-e1674762101800.jpg?resize=768%2C690&amp;ssl=1 768w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_privacy_day-2-e1674762101800.jpg?w=857&amp;ssl=1 857w\" sizes=\"auto, (max-width: 90px) 100vw, 90px\" \/><\/a> The Mailchimp security team identified an unauthorized actor had accessed tools used by Mailchimp customer-facing teams for customer support and account administration. The unauthorized actor conducted a social engineering attack on Mailchimp employees and contractors, and obtained access to Mailchimp accounts using employee credentials compromised in that attack.<\/p>\r\n<p>Impacted organizations include <a title=\"WooCommerce\" href=\"http:\/\/WooCommerce.com\/\" target=\"_blank\" rel=\"nofollow noopener\">WooCommerce<\/a>, online gambling site <a title=\"FanDuel\" href=\"https:\/\/www.fanduel.com\/\" target=\"_blank\" rel=\"nofollow noopener\">FanDuel<\/a>, Crypto darlings <a title=\"Yuga Labs\" href=\"https:\/\/www.yuga.com\/\" target=\"_blank\" rel=\"nofollow noopener\">Yuga Labs<\/a> and the <a title=\"https:\/\/solana.org\/\" href=\"https:\/\/solana.org\/\" target=\"_blank\" rel=\"nofollow noopener\">Solana Foundation<\/a>.<\/p>\r\n<p><a href=\"https:\/\/people.duke.edu\/~tkb13\/courses\/ncsu-csc405-2015fa\/\" target=\"_blank\" rel=\"noopener\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-116375\" title=\"CSC405: Introduction to Computer Security\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-9-e1643394085126-150x108.jpg?resize=100%2C72&#038;ssl=1\" alt=\"CSC405: Introduction to Computer Security\" width=\"100\" height=\"72\" \/><\/a>Mailchimp says they temporarily suspended account access for Mailchimp accounts where they detected suspicious activity to protect our users\u2019 data. They have notified the primary contacts for all affected accounts on January 12. Mailchimp has been working with their customers to help them reinstate their accounts.<\/p>\r\n<h3>Recent data breaches<\/h3>\r\n<p>MailChimp has announced several data breaches in recent months. In <a title=\"Information About a Recent Mailchimp Security Incident Targeting Crypot Companies\" href=\"https:\/\/mailchimp.com\/august-2022-security-incident\/\" target=\"_blank\" rel=\"nofollow noopener\">August 2022<\/a>, a cyberattack targeted its cryptocurrency-related customers. Mailchimp also revealed a <a title=\"Cryptocurrency coHackers breach MailChimp's internal tools to target crypto customersmpanies targeted in Mailchimp breach\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-breach-mailchimps-internal-tools-to-target-crypto-customers\/\" target=\"_blank\" rel=\"nofollow noopener\">security incident<\/a> in March 2022.<\/p>\r\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-113164\" title=\"data leak\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_leak-2-e1607483108233-150x98.png?resize=100%2C65&#038;ssl=1\" alt=\"data leak\" width=\"100\" height=\"65\" \/>Speculation is <a title=\"TurboTax, QuickBooks owner slammed after MailChimp data breach\" href=\"https:\/\/nypost.com\/2023\/01\/17\/turbotax-quickbooks-owner-slammed-for-mailchimp-data-breach\" target=\"_blank\" rel=\"nofollow noopener\">swirling online<\/a> about the security of parent company <a title=\"Intuit\" href=\"https:\/\/www.intuit.com\/\" target=\"_blank\" rel=\"nofollow noopener\">Intuit<\/a> other product lines (which includes <a title=\"TurboTax\" href=\"https:\/\/turbotax.intuit.com\/\" target=\"_blank\" rel=\"nofollow noopener\">TurboTax<\/a>, <a href=\"https:\/\/www.creditkarma.com\/\" target=\"_blank\" rel=\"nofollow noopener\">Credit Karma<\/a> and <a title=\"Quickbooks\" href=\"https:\/\/quickbooks.intuit.com\/\" target=\"_blank\" rel=\"nofollow noopener\">Quickbooks<\/a>). TurboTax suffered its own <a title=\"Intuit notifies customers of compromised TurboTax accounts\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/intuit-notifies-customers-of-compromised-turbotax-accounts\/\" target=\"_blank\" rel=\"nofollow noopener\">security breach<\/a> in 2021. <a title=\"Another Security Breach at Mailchimp; Customer Support Tools Again Hijacked to Phish Clients, in Third Such Incident in a Year\" href=\"https:\/\/www.cpomagazine.com\/cyber-security\/another-security-breach-at-mailchimp-customer-support-tools-again-hijacked-to-phish-clients-in-third-such-incident-in-a-year\/\" target=\"_blank\" rel=\"nofollow noopener\">Questions<\/a> are also being raised about a possible central backdoor into Intuit, which the company denies.<\/p>\r\n<p>If you have questions regarding a notice you received or the incident in general, please reach out you can email <a title=\"Mailchimp CISCO\" href=\"mailto:ciso@mailchimp.com\" target=\"_blank\" rel=\"nofollow noopener\">ciso@mailchimp.com<\/a>. The company has not announced the appointment of a new CISO since Siobhan Smyth left the position in August 2022 shortly after the August 2022 was announced.<\/p>\r\n<h3><em>rb-<\/em><\/h3>\r\n<p><em><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-127239\" title=\"multi-factor authentication\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2fa-2.png?resize=110%2C63&#038;ssl=1\" alt=\"multi-factor authentication\" width=\"110\" height=\"63\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2fa-2.png?resize=150%2C86&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2fa-2.png?resize=75%2C43&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/2fa-2.png?w=602&amp;ssl=1 602w\" sizes=\"auto, (max-width: 110px) 100vw, 110px\" \/>Information exposed in data breaches like this is commonly used by attackers to target users with phishing attacks or attempt to reset passwords to gain account authorization. This is why <a title=\"No Love for 2FA\" href=\"https:\/\/wp.me\/p2wgaW-tYR\" target=\"_blank\" rel=\"noopener\">multi-factor authentication<\/a> (MFA) can help. Even if the bogus password resets were successful the MFA can prevent the attacker from going further.<\/em><\/p>\r\n<p style=\"text-align: center;\"><em><strong><a href=\"https:\/\/www.obama.org\/updates\/help-ukraine\/\" target=\"_blank\" rel=\"nofollow noopener\">How you can help Ukraine!<\/a><\/strong><\/em><\/p>\r\n<p><strong>Related article<\/strong><\/p>\r\n<ul>\r\n<li><a title=\"T-Mobile hacked to steal data of 37 million accounts in API data breach\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/t-mobile-hacked-to-steal-data-of-37-million-accounts-in-api-data-breach\/\" target=\"_blank\" rel=\"nofollow noopener\">T-Mobile hacked to steal data of 37 million accounts in API data breach<\/a>\u00a0(<a title=\"Bleeping Computer\" href=\"https:\/\/www.bleepingcomputer.com\/\" target=\"_blank\" rel=\"nofollow noopener\">Bleeping Computer<\/a>)<\/li>\r\n<\/ul>\r\n<p>&nbsp;<\/p>\r\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a>\u00a0about IT, careers, and anything else that catches his attention since 2005. You can follow him on\u00a0<a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>Email service-provider Mailchimp has suffered a series of security breaches in the past year impacting online commerce, gambling, crypto and NFT sites.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[3652,3667,32,2755,125,3570,3665,3664,3594,2481,3668],"class_list":["post-127212","post","type-post","status-publish","format-standard","hentry","tag-3652","tag-bored-ape-yacht-club","tag-business","tag-cryptocurrency","tag-data-breach","tag-data-privacy-day","tag-intuit","tag-mailchimp","tag-nft","tag-social-engineering","tag-solana"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/127212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=127212"}],"version-history":[{"count":11,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/127212\/revisions"}],"predecessor-version":[{"id":127248,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/127212\/revisions\/127248"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=127212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=127212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=127212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}