On 26 March 2022, Mailchimp Security became aware of unauthorized access to an internal tool used for customer support and account administration. According to Mailchimp’s newsroom notice, CISO Siobhan Smyth stated the incident was propagated by a bad actor who conducted a successful social engineering attack on Mailchimp employees, resulting in employee credentials being compromised. Those credentials opened the internal tool. Mailchimp reported 319 accounts viewed and audience data exported from 102, focused on cryptocurrency and finance-related users. On 2 April 2022 the actor tried further phishing with data from the March access. Public reporting does not establish the social-engineering channel, any MFA method on the employee path, AiTM, device-code flow, or session-token theft.
If you want the prevention angle on workforce credential social engineering into support tooling, read the related article on mfa2point0.com.
FAQ
How did the Mailchimp March 2022 attackers get in?
The Mailchimp March 2022 attackers got in by socially engineering Mailchimp employees until employee credentials were compromised, then using those credentials on an internal customer-support and account-administration tool. According to Mailchimp’s 4 April 2022 newsroom notice and FAQ, that was the initial path. Public reporting does not establish whether the coaching was voice, email, chat, or another channel, and it does not name any MFA factor on the employee login.
What could the compromised Mailchimp employee credentials reach?
The compromised Mailchimp employee credentials reached an internal tool used to assist customers and administer accounts. Mailchimp’s official notice states 319 Mailchimp accounts were viewed and audience data was exported from 102 of those accounts. The company described the incident as targeted at users in industries related to cryptocurrency and finance. Public reporting does not itemize every field inside the exported audience data.
Did Mailchimp disclose MFA bypass, AiTM, or token theft?
Mailchimp did not disclose MFA bypass, AiTM, or token theft for the March 2022 incident. The documented story is social engineering that compromised employee credentials, then authenticated use of the internal support and account-administration tool. Public reporting does not establish TAP issuance, spoofed login pages, reverse-proxy kits, device-code phishing, cookie theft, or which second factor (if any) sat on those employee accounts.
What happened after the support-tool access at Mailchimp?
After the support-tool access at Mailchimp, the company opened an investigation, engaged outside forensics, and limited employee access to internal systems beginning 26 March 2022. According to the same notice, on 2 April 2022 a bad actor attempted further phishing using data obtained in the March attack. Mailchimp blocked access to a user account in that follow-on activity, but a phishing campaign still reached contacts through other means. Impacted account owners were notified.
Was this a workforce identity failure or a customer-app breach?
The Mailchimp March 2022 incident was a workforce identity failure first: employee credentials, after social engineering, opened internal support and admin tooling. Customer audience data exposure followed from that employee-path access, not from a consumer loyalty-app login. Closing a phishable employee credential path is the upstream control question; a fix for that class of workforce social engineering exists, without treating this notice as proof of any named MFA method.