Intuit Mailchimp A.I CyberSecurity Scoring
Intuit Mailchimp
Company Information
Website:http://mailchimp.com
Employees number:1,605
Number of followers:210,715
NAICS:5112
Industry Type:Software Development
Homepage:mailchimp.com
Intuit Mailchimp Risk Score (AI oriented)
Between 0 and 549
Intuit MailchimpSoftware Development
Updated:
30/03/2026
30/03/2026
289/1000
Critical
C
Intuit Mailchimp Global Score (TPRM)
xxxx
Intuit MailchimpSoftware Development
Score locked

Intuit MailchimpCritical
Current Score
289C (CRITICAL)
01000
6 incidents
-220.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
320
MAY 2026
305
APRIL 2026
298
MARCH 2026
289
FEBRUARY 2026
277
JANUARY 2026
267
DECEMBER 2025
254
NOVEMBER 2025
292
Breach
04 Nov 2025 • Intuit Mailchimp
Mailchimp
Troy Hunt Phishing Incident (Have I Been Pwned Founder)
231
HIGH-61
INT4203942110425
Troy Hunt, founder of Have I Been Pwned, fell victim to a phishing attack targeting his Mailchimp account earlier this year. The incident occurred due to human error—fatigue, jetlag, and a fear-triggering phishing email—leading him to bypass existing technical safeguards. The attack exploited the absence of phishing-resistant two-factor authentication (2FA), such as passkeys, on Mailchimp’s platform. His password manager failed to auto-complete credentials (a common issue), and he manually entered them on a spoofed login page. The breach underscored systemic vulnerabilities in Mailchimp’s security controls, particularly the reliance on outdated authentication methods and the lack of robust anti-phishing mechanisms. While the article does not specify the exact data compromised, phishing attacks of this nature often target employee or user credentials, which can escalate into broader account takeovers, data leaks, or downstream attacks on connected services. Hunt’s case highlights how even security-conscious individuals can be exploited, emphasizing the need for mandatory phishing-resistant MFA and behavioral AI-driven anomaly detection to mitigate human error. The incident reflects a broader trend where reused credentials (e.g., corporate emails tied to personal accounts) create attack vectors for threat actors, as seen in ransomware and credential-stuffing campaigns.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
290
SEPTEMBER 2025
278
AUGUST 2025
479
Ransomware
01 Aug 2025 • Intuit Mailchimp
Mailchimp
Ransomware operators Everest adds Mailchimp to their data leak site
254
CRITICAL-225
INT835080125
The ransomware group Everest claimed to have stolen 767 MB of sensitive data from email marketing giant Mailchimp. The stolen data includes 943,536 lines of internal company documents, which the group threatened to leak if Mailchimp did not pay a ransom. Despite the claim, the cybersecurity community mocked the size of the data leak, deeming it relatively small for a company of Mailchimp's size. The incident highlights the risks associated with ransomware attacks and the potential exposure of sensitive information.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
630
Ransomware
31 Jul 2025 • Intuit Mailchimp
Mailchimp
Mailchimp Data Breach by Everest Ransomware Group
254
CRITICAL-376
INT529080125
The Everest ransomware group claimed responsibility for breaching Mailchimp, a popular marketing platform. The group stole a 767 MB database containing 943,536 lines of data, including internal company documents and personal information of clients. The leaked dataset includes structured business information such as domain names, company emails, phone numbers, city and country details, GDPR region labels, social media links, and information about hosting providers. Many entries also list the technology stacks used by the companies.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2025
630
MARCH 2025
695
Breach
26 Mar 2025 • Intuit Mailchimp
Mailchimp
Mailchimp Data Breach
618
CRITICAL-77
INT814032625
Mailchimp experienced a phishing attack resulting in a data breach that compromised nearly 16,000 records of current and former mailing list subscribers. The phishing attack, targeted at Have I Been Pwned Administrator Troy Hunt, was executed through a malicious email that redirected to a fraudulent phishing site that captured Hunt's credentials. Despite the use of two-factor authentication, the automated nature of the attack allowed for rapid data extraction. Cloudflare has since taken down the phishing site, while the extent of data retention by Mailchimp from unsubscribed users remains unclear.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2023
712
Breach
01 Jan 2023 • Intuit Mailchimp
Intuit Mailchimp
MailChimp Social Engineering Attack
646
HIGH-66
INT20719123
MailChimp fell victim to a social engineering attack that threat actors successfully performed on the company`s employees and contractors.
Hackers managed to obtain employee credentials and gained access to an internal customer support and account administration tool which affected the data of 133 customers.
The information obtained by hackers only includes names, store URLs, addresses, and email addresses, which are still enough for threat actors to launch phishing attacks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2022
765
Breach
01 Apr 2022 • Intuit Mailchimp
Intuit Mailchimp
MailChimp Data Breach
702
CRITICAL-63
INT224512522
Email marketing firm MailChimp was targeted by hackers in a data breach incident.
The hackers gained access to internal customer support and account management tools to steal audience data and conduct phishing attacks.
The employees were also targeted in a social engineering attack that resulted in them losing their credential details.
These credentials were apparently used to access 319 MailChimp accounts and export audience data from 102 customer accounts and also to access API keys for a number of customers.
MailChimp notified all the impacted customers and recommended they enable two-factor authentication on their accounts.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Intuit Mailchimp ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in May 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in April 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in March 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in February 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in January 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in December 2025 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in November 2025 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in October 2025 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in September 2025 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in August 2025 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Intuit Mailchimp's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Intuit Mailchimp ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Intuit Mailchimp's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?