Wednesday, June 7, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Malware

MailChimp accounts hacked to spam out malicious emails

Researcher by Researcher
April 7, 2023
in Malware
0
MailChimp accounts hacked to spam out malicious emails
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Hackers broke into the MailChimp accounts of some businesses, and send out malicious invoice emails to subscribers… but that doesn’t mean that MailChimp suffered a serious security breach.

Once again, two-factor authentication could have saved users’ bacon.

Let me start with some full disclosure: I pay MailChimp a decent wedge of cash each month to send out newsletters to readers of my personal blog, and I’m quite a fan.

Related articles

Aggressive Android ransomware spreading in the USA

Aggressive Android ransomware spreading in the USA

April 11, 2023
The evolution of ransomware: From PC Cyborg to a service for sale

The evolution of ransomware: From PC Cyborg to a service for sale

April 11, 2023

Sending email to a large number of people reliably can be fraught with problems, and I would rather spend my time creating useful or interesting articles than trying to work out why my mail server is suddenly being blacklisted, or becoming entangled in the crazy cobweb of differences in how email clients handle even the simplest HTML.

And, perhaps, most importantly of all – I want to be sure that I don’t endanger the privacy of those people who have signed up for my mailing list by having their details spill into the hands of spammers.

FreddieMailChimp is one the world’s leading firms when it comes to email marketing and newsletter delivery.

They do a good job, and their sponsorship of popular podcasts, and use of Freddie the chimpanzee mascot (his full name is apparently Frederick Von Chimpenheimer IV) has helped them to grow an impressive brand.

But you can probably imagine that alarm bells rang when I read a story on Motherboard saying that hackers had broken into business’s MailChimp accounts, and sent out emails to subscribers containing malicious links.

The emails bore the disguise of a QuickBooks invoice, and were sent to various mailing lists including subscribers of the Sit Down Comedy Club in Brisbane, Australia:

Malicious email

According to Motherboard, the Sit Down Comedy Club has an auto-responder on its email account, telling anyone who received the malicious email entitled “Inoice 00317” to delete it immediately:

“IF YOU RECEIVE AN EMAIL WITH THE TITLE – Inoice 00317 from Sit Down Comedy Club Pty Ltd – PLEASE DELETE the email you received, we do not use Quickbooks. It is SPAM and do not open it.”

The fact that the comedy club went to the effort of setting up an auto-response suggests that they must have received a lot of emails from folks wondering why on earth they had received an invoice from them.

Another corporate victim of the hackers was the Business News Australia website, which sent out a follow-up email to its mailing list telling subscribers to delete the malicious email. Australian security blogger Troy Hunt received the email, and in a tweet pointed a finger of suspicion at poor password security.

Troy Hunt tweet

So, as a MailChimp customer, should I be panicking that my own account may have been compromised by hackers and might at any moment be hijacked to send out malicious invoices?

I don’t think so.

You see, I think Troy is right. This is unlikely to be a security breach at MailChimp itself. I believe that what is more likely to have occurred is that individual accounts at MailChimp were broken into through the simple means of criminals either successfully phishing for credentials, or a perennial problem like password reuse.

My hunch is that the affected MailChimp users had not adopted the additional protection of enabling two-factor authentication on their accounts.

Multi-factor authentication means that even if your password is stolen by a hacker, they should find it an uphill struggle to break into your account because they don’t have access to the (ever-changing) passcode generated by your authenticator app.

mailchimp-2fa

Sue enough, in a statement to Motherboard, MailChimp confirmed that it was not suffering a system-wide breach, but that instead individual accounts had been accessed by unauthorised parties in order to spam out the malicious messages:

Early this morning MailChimp’s normal compliance processes identified and disabled a small number of individual accounts sending fake invoices. We have investigated the situation and have found no evidence that MailChimp has been breached. The affected accounts have been disabled, and fraudulent activity has stopped.

There really is no excuse for not enabling two-factor authentication whenever a site makes it available to you, and that’s particularly true in MailChimp’s case because they actually offer a 10% discount for customers who have chosen to secure their accounts more tightly.

A cynic might argue that offering a 10% discount for customers who use two-factor authentication is just a different way of saying that MailChimp charges 10% more for people who don’t enable two-factor authentication. And I guess that they would be right.

But it’s good marketing, isn’t it?





Source link

Tags: accountsEmailsHackedMailChimpMaliciousspam
Share76Tweet47

Related Posts

Aggressive Android ransomware spreading in the USA

Aggressive Android ransomware spreading in the USA

April 11, 2023
0

The latest ESET discovery of the first known Android lock-screen-type ransomware that spreads in the wild and sets the phone’s...

The evolution of ransomware: From PC Cyborg to a service for sale

The evolution of ransomware: From PC Cyborg to a service for sale

April 11, 2023
0

A look back at how ransomware – a type of malware used mostly for hijacking user data – has evolved...

Using DroidJack to spy on an Android? Expect a visit from the police

Using DroidJack to spy on an Android? Expect a visit from the police

April 11, 2023
0

Law enforcement agencies across Europe have searched homes this week, as part of an international crackdown against users of a...

Fighting talk from Great Britain as it says it will hit back against internet attacks

Fighting talk from Great Britain as it says it will hit back against internet attacks

April 11, 2023
0

British chancellor George Osborne has warned about the spectre of online terrorists attacking national infrastructure, and made some rather bold...

Police arrest couple suspected of running malware encryption service

Police arrest couple suspected of running malware encryption service

April 10, 2023
0

British police arrested a man and a woman earlier this week, suspected of operating a website which offered services to...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Apple launches Vision Pro & more new products

Apple launches Vision Pro & more new products

June 7, 2023
Ransomware, DDoS see major upsurge led by upstart hacker group

DDoS attacks dominate and pretexting lead to BEC growth

June 7, 2023
Money20/20 Europe 2023: Day One TFT Roundup

Money20/20 Europe 2023: Day One TFT Roundup

June 7, 2023
Release date, price and more

Release date, price and more

June 7, 2023

Recent Posts

Apple launches Vision Pro & more new products

Apple launches Vision Pro & more new products

June 7, 2023
Ransomware, DDoS see major upsurge led by upstart hacker group

DDoS attacks dominate and pretexting lead to BEC growth

June 7, 2023
Money20/20 Europe 2023: Day One TFT Roundup

Money20/20 Europe 2023: Day One TFT Roundup

June 7, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved