Email marketing company MailChimp recently suffered another data breach when hackers managed to infiltrate and exploit the company's internal customer support and account management tool. The attack compromised the personal information of a total of 133 customers.
See also: MailChimp breached by hackers targeting the crypto industry

After a social engineering on MailChimp employees and contractors, attackers were able to gain access to employee credentials, the company said. On January 11, MailChimp identified an attacker using its support system and launched an investigation into the attack.
“To protect our valued users from a data breach, we identified suspicious activity and quickly suspended access to Mailchimp accounts where unauthorized parties were present. This statement explains the course of action we took for security reasons..”
“To ensure swift action, we notified all relevant contacts of the affected accounts within one day of the initial discovery on January 12th.“
“We at MailChimp take the utmost care in the security of our customers' data and are relieved to inform you that no credit card information or passwords were exposed as a result of this incident.“
See also: Nissan North America: Revealed a customer data breach
As TechCrunch first reported, one of the victims of this breach was WooCommerce. WooCommerce is an open-source plugin for WordPress websites. It was created in 2011 by Automattic, the company behind WordPress.com. Since then, it has become one of the most popular e-commerce solutions on the internet with over 1 million active installations worldwide. It allows users to quickly and easily turn their website into a fully functional online store.

WooCommerce sent an urgent notification to its customers, warning them that the MailChimp security breach exposed personal information such as names, addresses, store URLs, and email addresses.
Although WooCommerce has found no evidence of misuse of the compromised data, it is common for hackers to use such information in phishing aimed at stealing credentials or deploying malware.
In April 2022, Trezor wallet owners began receiving fake data breach notifications asking them to download a fake version of the software titled “Trezor Suite.” This malicious code was designed with one purpose in mind: to steal recovery resources from unsuspecting customers.
See also: Norton LifeLock: Thousands of customer accounts breached
According to Trezor’s Twitter post, the mailing list used in this malicious phishing attack was obtained through a MailChimp breach and was originally taken from its official mailing list. Upon further investigation, MailChimp discovered a wider scope of the security breach, with employees being tricked by a social engineering attack that allowed the attackers to gain access to 319 accounts and extract data from 102 customers.
