By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Creator of HaveIBeenPwned Data Breach Site Falls for Phishing Email
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Creator of HaveIBeenPwned Data Breach Site Falls for Phishing Email
News

Creator of HaveIBeenPwned Data Breach Site Falls for Phishing Email

News Room
Last updated: 2025/03/25 at 6:43 PM
News Room Published 25 March 2025
Share
SHARE

A hacker has managed to phish Troy Hunt, the creator of HaveIBeenPwned.com, tricking the security expert into clicking a malicious email while he was jetlagged. 

The breach affects people who subscribed to Hunt’s personal blog, rather than HaveIBeenPwned, a data breach notification site that’s attracted millions of users. “I’m enormously frustrated with myself for having fallen for this, and I apologize to anyone on that list,” he said. 

The Best Amazon Spring Sale Deals You Can Get Now

*Deals are selected by our commerce team

On Tuesday, Hunt disclosed the breach, which affects 16,000 email addresses. The attack  occurred through a phishing message that pretended to come from his email provider Mailchimp. The phishing email claimed that Mailchimp had received a spam complaint and was forced to restrict “sending privileges” to Hunt’s account tied to his personal blog. 


This Tweet is currently unavailable. It might be loading or has been removed.

Hunt clicked on the phishing email, which led him to enter his credentials and one-time passcode into a hacker-controlled login page. But he quickly realized something was off when the login process “hung.” Hunt changed his password to his real Mailchimp account, but it was too late: The hacker had breached his account, and exported his mailing list — suggesting the entire attack was automated. 

Hunt adds that 7,535 users that had unsubscribed to his blog were also ensnared in the hack due to Mailchimp failing to delete their emails. 

Hunt, who’s Australian, says he fell for the phishing scheme while visiting government partners in London. Although he’s received and fended off a “gazillion similar phishes before,” Hunt said this particular phishing email caught him off guard because he was exhausted from traveling.

“Tiredness, was a major factor. I wasn’t alert enough, and I didn’t properly think through what I was doing,” he wrote on his own blog. “The attacker had no way of knowing that (I don’t have any reason to suspect this was targeted specifically at me), but we all have moments of weakness and if the phish times just perfectly with that, well, here we are.”

The malicious email (Credit: Troy Hunt)

Like other phishing scams, the malicious email successfully created a sense of urgency and exploited Hunt’s fears by fooling him into thinking Mailchimp was about to suspend his newsletter. “It wasn’t all bells and whistles about something terrible happening if I didn’t take immediate action. It created just the right amount of urgency without being over the top,” he said. 

Recommended by Our Editors

The hack also underscores how two-factor authentication isn’t bulletproof. Hunt’s Mailchimp account had 2FA activated, but the phishing attack was still able to trick him into giving up a one-time passcode, which it quickly used to break into his account. “Let this be a lesson as to how completely useless it is against an automated phishing attack that can simply relay the OTP as soon as it’s entered,” he said. 

In response, he’s asked Mailchimp about whether the company plans on offering passkeys, which can stop such phishing attacks. He’s also wondering why Mailchimp didn’t delete the email addresses of people who unsubscribed to his blog.   

In the meantime, Hunt is notifying affected users through email. Mailchimp didn’t immediately respond to a request for comment

Newsletter Icon

Like What You’re Reading?

Sign up for SecurityWatch newsletter for our top privacy and security stories delivered right to your inbox.

This newsletter may contain advertising, deals, or affiliate links.
By clicking the button, you confirm you are 16+ and agree to our
Terms of Use and
Privacy Policy.
You may unsubscribe from the newsletters at any time.

Newsletter Pointer

About Michael Kan

Senior Reporter

Michael Kan

I’ve been working as a journalist for over 15 years—I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017.

Read Michael’s full bio

Read the latest from Michael Kan

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Track your valuables on the cheap with this tempting Tile offer
Next Article Adaptive Ascension: LLMs, Efficiency, and Query Complexity | HackerNoon
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Soviet spacecraft CRASHES into Earth after getting stuck in orbit for 50 years
News
Huawei’s PC chipset contingency plan does not exist, Huawei staff say · TechNode
Computing
Today's NYT Connections Hints, Answers for May 11, #700
News
Top Stories: iOS 18.5 Release Imminent, iPhone Rumors for 2025 and Beyond, and More
News

You Might also Like

News

Soviet spacecraft CRASHES into Earth after getting stuck in orbit for 50 years

3 Min Read
News

Today's NYT Connections Hints, Answers for May 11, #700

3 Min Read
News

Top Stories: iOS 18.5 Release Imminent, iPhone Rumors for 2025 and Beyond, and More

7 Min Read
News

Eufy Robot Lawn Mower E18 Review: Autonomous Grass Cutting Made Easy

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?