Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Intuit Mailchimp

Intuit Mailchimp Vendor Cyber Rating & Cyber Score

mailchimp.com

The Mailchimpossibilities are endless when you create, automate, and optimize your marketing with Mailchimp.


Intuit Mailchimp A.I CyberSecurity Scoring

Intuit Mailchimp
Company Information
Website:http://mailchimp.com
Employees number:1,605
Number of followers:210,715
NAICS:5112
Industry Type:Software Development
Homepage:mailchimp.com
Intuit Mailchimp Risk Score (AI oriented)
Between 0 and 549
logo
Intuit MailchimpSoftware Development
Updated:
30/03/2026
289/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Intuit Mailchimp Global Score (TPRM)
xxxx
logo
Intuit MailchimpSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Intuit Mailchimp
Intuit MailchimpCritical
Current Score
289C (CRITICAL)
01000
6 incidents
-220.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
320Before Incident
MAY 2026
305Before Incident
APRIL 2026
298Before Incident
MARCH 2026
289Before Incident
FEBRUARY 2026
277Before Incident
JANUARY 2026
267Before Incident
DECEMBER 2025
254Before Incident
NOVEMBER 2025
292Before Incident
Breach
04 Nov 2025Intuit Mailchimp
Mailchimp

Troy Hunt Phishing Incident (Have I Been Pwned Founder)

231After Incident
HIGH-61
INT4203942110425
Troy Hunt, founder of Have I Been Pwned, fell victim to a phishing attack targeting his Mailchimp account earlier this year. The incident occurred due to human error—fatigue, jetlag, and a fear-triggering phishing email—leading him to bypass existing technical safeguards. The attack exploited the absence of phishing-resistant two-factor authentication (2FA), such as passkeys, on Mailchimp’s platform. His password manager failed to auto-complete credentials (a common issue), and he manually entered them on a spoofed login page. The breach underscored systemic vulnerabilities in Mailchimp’s security controls, particularly the reliance on outdated authentication methods and the lack of robust anti-phishing mechanisms. While the article does not specify the exact data compromised, phishing attacks of this nature often target employee or user credentials, which can escalate into broader account takeovers, data leaks, or downstream attacks on connected services. Hunt’s case highlights how even security-conscious individuals can be exploited, emphasizing the need for mandatory phishing-resistant MFA and behavioral AI-driven anomaly detection to mitigate human error. The incident reflects a broader trend where reused credentials (e.g., corporate emails tied to personal accounts) create attack vectors for threat actors, as seen in ransomware and credential-stuffing campaigns.
INCIDENT DETAILS -
TYPE
PhishingSocial Engineering
MOTIVATION
Credential TheftAccount Takeover
IMPACT
Personal Credentials (Mailchimp Account)Mailchimp AccountBrand Reputation Impact: Minimal (publicly disclosed as a learning example)Identity Theft Risk: Potential (if credentials reused elsewhere)
DATA BREACH
Email CredentialsNumber Of Records Exposed: 1 (Personal Account)Sensitivity Of Data: Moderate (Potential for Reuse in Other Services)Email AddressPassword
OCTOBER 2025
290Before Incident
SEPTEMBER 2025
278Before Incident
AUGUST 2025
479Before Incident
Ransomware
01 Aug 2025Intuit Mailchimp
Mailchimp

Ransomware operators Everest adds Mailchimp to their data leak site

254After Incident
CRITICAL-225
INT835080125
The ransomware group Everest claimed to have stolen 767 MB of sensitive data from email marketing giant Mailchimp. The stolen data includes 943,536 lines of internal company documents, which the group threatened to leak if Mailchimp did not pay a ransom. Despite the claim, the cybersecurity community mocked the size of the data leak, deeming it relatively small for a company of Mailchimp's size. The incident highlights the risks associated with ransomware attacks and the potential exposure of sensitive information.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: Internal company documentsBrand Reputation Impact: Mockery from the cybersecurity community
DATA BREACH
Type Of Data Compromised: Internal company documentsNumber Of Records Exposed: 943,536 linesSensitivity Of Data: SensitiveData Exfiltration: Yes
AUGUST 2025
630Before Incident
Ransomware
31 Jul 2025Intuit Mailchimp
Mailchimp

Mailchimp Data Breach by Everest Ransomware Group

254After Incident
CRITICAL-376
INT529080125
The Everest ransomware group claimed responsibility for breaching Mailchimp, a popular marketing platform. The group stole a 767 MB database containing 943,536 lines of data, including internal company documents and personal information of clients. The leaked dataset includes structured business information such as domain names, company emails, phone numbers, city and country details, GDPR region labels, social media links, and information about hosting providers. Many entries also list the technology stacks used by the companies.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Double Extortion (Encryption and Data Theft)
IMPACT
internal company documentspersonal documents and information of clients
DATA BREACH
domain namescompany emailsphone numberscity and country detailsGDPR region labelssocial media linksinformation about hosting providerstechnology stacksSensitivity Of Data: Mediumspreadsheet-style rows
JULY 2025
630Before Incident
MARCH 2025
695Before Incident
Breach
26 Mar 2025Intuit Mailchimp
Mailchimp

Mailchimp Data Breach

618After Incident
CRITICAL-77
INT814032625
Mailchimp experienced a phishing attack resulting in a data breach that compromised nearly 16,000 records of current and former mailing list subscribers. The phishing attack, targeted at Have I Been Pwned Administrator Troy Hunt, was executed through a malicious email that redirected to a fraudulent phishing site that captured Hunt's credentials. Despite the use of two-factor authentication, the automated nature of the attack allowed for rapid data extraction. Cloudflare has since taken down the phishing site, while the extent of data retention by Mailchimp from unsubscribed users remains unclear.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: 16,000 records
DATA BREACH
Number Of Records Exposed: 16,000
JANUARY 2023
712Before Incident
Breach
01 Jan 2023Intuit Mailchimp
Intuit Mailchimp

MailChimp Social Engineering Attack

646After Incident
HIGH-66
INT20719123
MailChimp fell victim to a social engineering attack that threat actors successfully performed on the company`s employees and contractors. Hackers managed to obtain employee credentials and gained access to an internal customer support and account administration tool which affected the data of 133 customers. The information obtained by hackers only includes names, store URLs, addresses, and email addresses, which are still enough for threat actors to launch phishing attacks.
INCIDENT DETAILS -
TYPE
Social Engineering Attack
MOTIVATION
Data theft for potential phishing attacks
IMPACT
namesstore URLsaddressesemail addressesinternal customer support and account administration tool
DATA BREACH
namesstore URLsaddressesemail addressesSensitivity Of Data: Medium
APRIL 2022
765Before Incident
Breach
01 Apr 2022Intuit Mailchimp
Intuit Mailchimp

MailChimp Data Breach

702After Incident
CRITICAL-63
INT224512522
Email marketing firm MailChimp was targeted by hackers in a data breach incident. The hackers gained access to internal customer support and account management tools to steal audience data and conduct phishing attacks. The employees were also targeted in a social engineering attack that resulted in them losing their credential details. These credentials were apparently used to access 319 MailChimp accounts and export audience data from 102 customer accounts and also to access API keys for a number of customers. MailChimp notified all the impacted customers and recommended they enable two-factor authentication on their accounts.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
Audience DataAPI KeysCustomer Support ToolsAccount Management Tools
DATA BREACH
Audience DataAPI Keys

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Intuit Mailchimp ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Intuit Mailchimp's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Intuit Mailchimp ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Intuit Mailchimp's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?