A Sneaky Phish Just Grabbed my Mailchimp Mailing List
ID: 2a11914c-7b2b-5d5a-986c-db29fc5f5e83
STIX ID: report--2a11914c-7b2b-5d5a-986c-db29fc5f5e83
Feed Name: Troy Hunt – Security Blog
Troy Hunt recounts being phished via a Mailchimp lookalike site that harvested his credentials and one-time password, enabling an automated export of approximately 16,000 subscriber records (including unsubscribed addresses). He documents alerts showing the login and export from another IP, the creation and deletion of an API key, coordination with Mailchimp to restore and secure the account, the limitations of OTP-based 2FA against relay phishing, concerns about retained unsubscribed addresses, and follow-up investigation including possible links to the Scattered Spider group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
