On 11 January 2023 Mailchimp’s security team found an unauthorized actor inside a customer support and account-administration tool. According to Mailchimp’s January 2023 security incident notice, updated 17 January 2023, the actor socially engineered Mailchimp employees and contractors, compromised employee credentials in that attack, and used those credentials to reach selected customer accounts. Mailchimp said the targeted incident was limited to 133 Mailchimp accounts, notified primary contacts in under 24 hours, and temporarily suspended access where it saw suspicious activity. Public reporting does not name a more specific social-engineering method, a threat actor, or whether MFA was present on those workforce logins.
If you want the prevention angle on workforce credential social engineering and support-tool step-up, read the related article on mfa2point0.com.
FAQ
How did the Mailchimp January 2023 attackers get in?
The Mailchimp January 2023 attackers got in by socially engineering Mailchimp employees and contractors and obtaining employee credentials. According to Mailchimp’s official notice, those compromised workforce credentials were then used to access a customer support and account-administration tool. Public reporting does not establish whether the coaching was a fake login page, a helpdesk reset, a voice call, or another method.
What did stolen Mailchimp employee credentials unlock?
Stolen Mailchimp employee credentials unlocked unauthorized use of a customer support and account-administration tool against selected customer accounts. Mailchimp stated the incident was limited to 133 Mailchimp accounts. That access is residual use of valid workforce credentials on privileged tooling, not a separate break of each customer’s own login.
Did Mailchimp name the social-engineering method or MFA failure?
Mailchimp did not name a specific social-engineering method beyond targeting employees and contractors, and it did not describe MFA use or any MFA bypass in the published notice. Public reporting does not establish TAP issuance, an AiTM proxy, device-code phishing, push fatigue, or a named authenticator factor. The documented fact is compromised employee credentials after social engineering.
How many accounts were affected and how fast did Mailchimp respond?
Mailchimp said 133 Mailchimp customer accounts were affected. The security team identified the unauthorized access on 11 January 2023, notified primary contacts for affected accounts on 12 January 2023 (less than 24 hours after discovery), published the notice on 13 January 2023, and updated it on 17 January 2023. Mailchimp also said it saw no indication the compromise affected Intuit systems or customer data beyond those 133 Mailchimp accounts.
Would stronger workforce authentication have changed this path?
Stronger workforce authentication that removes coachable shared secrets can shrink the path where socially engineered employee credentials alone open support and admin tooling. Mailchimp’s notice still frames initial access as compromised employee credentials after social engineering, so closing that credential surface is the upstream control. A fix for that class of workforce identity failure exists; the prevention write-up is on the companion site.