Email marketing company MailChimp revealed on Sunday that it was hit by hackers who gained access to internal customer support and account management tools to steal audience data and carry out phishing attacks.
See also: United Kingdom: Two teenagers linked to Lapsus$ hacking group

The breach was confirmed to the press by Mailchimp on Monday, but had come to light over the weekend when users of the Trezor hardware cryptocurrency wallet reported being targeted by sophisticated phishing emails.
On Sunday morning, Twitter was filled with reports from owners of Trezor cryptocurrency hardware wallets who received phishing alerts claiming that the company had suffered a data breach.
These emails prompted Trezor customers to reset their hardware wallet PINs by downloading malware that allowed the theft of stored cryptocurrency.

Trezor later shared that MailChimp had been compromised by threats targeting the cryptocurrency industry, which carried out the phishing attack.
MailChimp breach targets crypto, finance
In an email to BleepingComputer, MailChimp confirmed that the breach was more significant than the threat actors gaining access to the Trezor account.
According to MailChimp, some of their employees fell victim to a social engineering attack that led to the theft of their credentials.
In a statement sent to The Verge, Siobhan Smyth, Mailchimp’s CISO, said the company was notified of the breach on March 26 when it detected unauthorized access to a tool used by the company’s customer support and account management teams. Although Mailchimp disabled the compromised employee accounts after learning of the breach, the hackers were still able to view about 300 Mailchimp user accounts and obtain audience data from 102 of them, Smyth said.
See also: Russia's secret police: How details were leaked
In addition to viewing accounts and extracting data, the threat actors gained access to API keys for an unknown number of customers, which have now been deactivated and can no longer be used.
Application Programming Interface (API) keys are access tokens that allow MailChimp customers to manage their accounts and run marketing campaigns directly from their own websites or platforms.
Using these compromised API keys, a threat actor can create customized email campaigns, such as phishing campaigns, and send them to mailing lists without access to MailChimp's customer portal.

Smyth told BleepingComputer that all compromised account holders have been notified and that the threat actors had access to customers in the cryptocurrency and financial sectors.
MailChimp says it has received reports that this access was used to conduct phishing against stolen contacts, but has not disclosed information about these attacks.
See also: VMware patches Spring4Shell vulnerability affecting several of its products
MailChimp recommends that all customers enable two-factor authentication on their accounts for further protection.
Information source: bleepingcomputer.com
