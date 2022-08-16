Mailchimp suffered another data breach earlier this month, and this one cost it a client.

In a statement Friday, Mailchimp disclosed that a security incident involving phishing and social engineering tactics had targeted cryptocurrency and blockchain companies using the email marketing platform. It was the second Mailchimp breach to target cryptocurrency customers in a four-month span.

Though Mailchimp said it has suspended accounts where suspicious activity was detected while an investigation is ongoing, it did not reveal the source of the breach or scope of the attack.

More details were provided Sunday by one of the affected customers, DigitalOcean, which cut ties with Mailchimp on Aug. 9.

The cloud hosting provider observed suspicious activity beginning Aug. 8, when threat actors used its Mailchimp account for "a small number of attempted compromises" of DigitalOcean customer accounts -- specifically cryptocurrency platforms.

While it is not clear whether any DigitalOcean accounts were compromised, the company did confirm that some email addresses were exposed. More importantly, the statement attributed a potential source of the most recent Mailchimp breach.

"We were formally notified on August 10th by Mailchimp of the unauthorized access to our and other accounts by what we understand to be an attacker who had compromised Mailchimp internal tooling," DigitalOcean wrote in a statement.

In the earlier breach, which was disclosed in April, Mailchimp CISO Siobhan Smyth said threat actors gained control of the company's internal tooling, which led the attacker to gain access to employee credentials and use the information for targeted phishing attacks of cryptocurrency platform customers.

Mailchimp sent the following statement to TechTarget Editorial regarding the latest attack:

We recently experienced a security incident in which unauthorized actors targeted Mailchimp's crypto-related users by employing sophisticated phishing and social engineering tactics. Based on our investigation to date, it appears that 214 Mailchimp accounts were affected by the incident. In an abundance of caution, when we detect suspicious activity in our users' accounts, we take proactive steps to temporarily suspend account access. All owners of impacted accounts have been notified, and we're working diligently to reinstate accounts. We are continuing our investigation and proactively providing impacted users with timely and accurate information throughout the process.