Skip to main content


It finally happened - I got phished. Impact is limited to the Mailchimp mailing list for my blog, brief blog post with details here and more to come later: troyhunt.com/a-sneaky-phish-ju…

Pseudo Nym reshared this.

in reply to Troy Hunt

Argh, sorry for you!

Interesting point:

> The export also includes [the email address of] people who've unsubscribed.

Curious to know what Mailchimp has to say about it.

This entry was edited (4 months ago)
in reply to Troy Hunt

I have to admit not knowing how passkeys protect against this. I've been under the impression that a password manager and passkeys have the same security.

(And yes, I agree - it's a problem sites use so many different authentication endpoints that we're used to our password managers not being able to autofill!)

in reply to Troy Hunt

Thank you for the writeup.

This just goes to show that ANYONE can be targeted and compromised.

It's not if, it's when. We need to plan accordingly.

in reply to Troy Hunt

For everyone who asked "why did Mailchimp keep my email address after I unsubscribed?", see Update 3 in the blog post above. I think this can be done much better, but it does answer the question.