logo

A Sneaky Phish Just Grabbed my Mailchimp Mailing List

ID: 2a11914c-7b2b-5d5a-986c-db29fc5f5e83

STIX ID: report--2a11914c-7b2b-5d5a-986c-db29fc5f5e83

Feed Name: Troy Hunt – Security Blog

Threat Score
55/100

Date Published: 2025-03-25

Date Updated: 2026-04-19

Author: Troy Hunt

...
...

Troy Hunt recounts being phished via a Mailchimp lookalike site that harvested his credentials and one-time password, enabling an automated export of approximately 16,000 subscriber records (including unsubscribed addresses). He documents alerts showing the login and export from another IP, the creation and deletion of an API key, coordination with Mailchimp to restore and secure the account, the limitations of OTP-based 2FA against relay phishing, concerns about retained unsubscribed addresses, and follow-up investigation including possible links to the Scattered Spider group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.