This is to inform you about a security breach that has taken place at the emailing provider Mailchimp, one of the biggest email service-providers worldwide. This breach allowed an unauthorized actor to download data associated to 133 customers of the Mailchimp service (including name and email address).
Please note that no password information was exposed and the recipient accounts have not been impacted by this incident.
Mailchimp published details about their security breach here.
Please note that Mailchimp customers have informed the data protection authorities and have confirmed with Mailchimp that their accounts are secure and follow all security best practices. For operational security reasons Mailchimp is not publicly commenting on actions they are taking.
What can you do as an (potential) affected user now? We recommend you to be particularly attentive to phishing emails over the course of the upcoming months.
FAQ:
Do third parties now have access to the payment method or password that I used to purchase goods or services?
No, the security vulnerability at Mailchimp only affects contact data stored on Mailchimp servers. This was not a breach of Mailchimp customers.
Do third parties now have access to my account?
No, there is no password information stored on Mailchimp servers.
Which kind of data has been exposed?
Email address, Surname and Name.
Have the authorities been informed?
Yes. Mailchimp itself is legally obliged to report the incident. In addition, Mailchimp customers have informed the data protection commissioner.