Intuit Mailchimp A.I CyberSecurity Scoring
Intuit Mailchimp
Company Information
Website:http://mailchimp.com
Employees number:1,610
Number of followers:210,677
NAICS:5112
Industry Type:Software Development
Homepage:mailchimp.com
Intuit Mailchimp Risk Score (AI oriented)
Between 550 and 599
Intuit MailchimpSoftware Development
Updated:
20/04/2026
20/04/2026
567/1000
Very Poor
Ca
Intuit Mailchimp Global Score (TPRM)
xxxx
Intuit MailchimpSoftware Development
Score locked

Intuit MailchimpVery Poor
Current Score
567Ca (VERY POOR)
01000
4 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
584
AUGUST 2026
580
JULY 2026
577
JUNE 2026
575
MAY 2026
571
APRIL 2026
568
MARCH 2026
564
FEBRUARY 2026
595
JANUARY 2026
557
DECEMBER 2025
588
NOVEMBER 2025
587
OCTOBER 2025
583
AUGUST 2025
723
Ransomware
01 Aug 2025 • Intuit Mailchimp
Mailchimp and Vimeo: Mailchimp hit by alleged ransomware attack
Mailchimp Hit by Everest Ransomware Group in Data Theft Attack
573
CRITICAL-150
VIMMAI1770775106
Mailchimp Hit by Everest Ransomware Group in Data Theft Attack
The Everest ransomware group has claimed responsibility for a cyberattack on Mailchimp, the direct marketing platform with over 14 million users, including major brands like The North Face, Vimeo, and New Belgium Brewing. On July 31, the group posted details of the breach on its darknet leak site, alleging the theft of 767 MB of data approximately 943,536 lines of information.
The stolen data includes internal company documents, client personal information, and corporate details, such as:
- Company domain names and emails
- Location data and phone numbers
- Social media links
- GDPR-related labels
- Tech stack details of companies like Amazon, PayPal, and Shopify
Everest provided two screenshots of the data, which appear to have been exported from a customer relationship management (CRM) platform. Notably, the group has not issued a ransom demand or deadline, and Mailchimp is one of four victims listed on the same day.
Everest, a Russian-linked ransomware group active since 2020, initially operated as a data-theft extortion operation before expanding into ransomware and encryption. The group has claimed 238 victims to date, with recent attacks including:
- Coca-Cola’s Middle Eastern bottling partner (May 2024)
- South African healthcare giant Mediclinic
- Australian behavioral science firm Evidn (earlier in 2024)
Mailchimp has not yet publicly responded to the breach. The incident highlights the ongoing threat posed by ransomware groups targeting high-profile marketing and customer data platforms.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2023
748
Data Leak
01 Jan 2023 • Intuit Mailchimp
Intuit Mailchimp
Mailchimp Data Hack
687
MEDIUM-61
INT224981023
Numerous organizations have been impacted by the latest Mailchimp data hack; some of them have already notified their customers.
To acquire access to a tool for internal assistance and account administration, threat actors targeted the company's workers and contractors.
The business also stated that there is no proof that this security compromise affected Intuit systems or any other customer data in addition to the 133 accounts that were reported.
Customers were warned by the business that some of their information, including name, URL, address, and email address, may have been compromised. Payment information, passwords, or any other sensitive information was not exposed, according to WooCommerce.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2021
741
Breach
01 Sep 2021 • Intuit Mailchimp
MailChimp, Caesars, Riot Games and MGM Resorts: British Scattered Spider hacker pleads guilty to crypto theft charges
Scattered Spider Leader Pleads Guilty in $8M Cryptocurrency Heist
638
CRITICAL-103
MGMMAIRIOCAE1776695654
Scattered Spider Leader Pleads Guilty in $8M Cryptocurrency Heist
A 24-year-old British national, Tyler Robert Buchanan alleged leader of the cybercrime group Scattered Spider has pleaded guilty in the U.S. to charges of wire fraud and aggravated identity theft. Prosecutors accuse Buchanan and four co-conspirators of stealing at least $8 million in cryptocurrency between September 2021 and April 2023 through a series of SMS phishing (smishing) attacks targeting employees at over a dozen companies.
The victims spanned multiple industries, including entertainment, telecommunications, IT, cloud communications, and cryptocurrency services. The group used fraudulent text messages impersonating legitimate IT or business process outsourcing (BPO) suppliers, directing victims to fake login pages to harvest credentials. With stolen access, they executed SIM swap attacks, hijacking phone numbers and cryptocurrency wallets to siphon funds.
Buchanan was arrested in June 2024 in Palma de Mallorca, Spain, and has been in U.S. custody since April 2025. He faces a maximum sentence of 22 years and is scheduled for sentencing on August 21, 2026. Three accomplices Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo, and Joel Martin Evans were charged in November 2024 with similar offenses, carrying potential 20-year prison terms. A fourth member, Noah Michael Urban (aka Sosa/Elijah), was sentenced to 10 years in 2024 after pleading guilty to related charges.
Scattered Spider, also known as 0ktapus, UNC3944, and Octo Tempest, is a loosely organized, English-speaking collective of young hackers (some as young as 16) that operates via Telegram, Discord, and hacker forums. The group employs social engineering, MFA bombing, and SIM swapping to breach corporate networks. Since 2023, they have collaborated with Russian ransomware gangs, including BlackCat/AlphV, Qilin, and RansomHub.
Notable attacks linked to Scattered Spider include breaches at MGM Resorts, Caesars, Riot Games, MailChimp, Twilio, DoorDash, and Reddit. In July 2024, UK authorities arrested a 17-year-old suspect tied to the 2023 MGM ransomware attack, further underscoring the group’s role in high-profile cybercrime.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2018
765
Breach
01 Jan 2018 • Intuit Mailchimp
Mailchimp
MailChimp Email Address Leak
706
CRITICAL-59
MAI225320522
MailChimp had been leaking respondents’ email addresses.
The issue could expose personal information.
If one visit a link from a MailChimp newsletter, his email address and reading habits can be compromised to a site owner.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Intuit Mailchimp ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in August 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in July 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in June 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in May 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in April 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in March 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in February 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in January 2026 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in December 2025 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in November 2025 ??
What was Intuit Mailchimp's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Intuit Mailchimp's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Intuit Mailchimp ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Intuit Mailchimp's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?