News: 1650924945

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Intuit sued over alleged cryptocurrency thefts via Mailchimp intrusion

(2022/04/26)


Intuit is being sued in the US after a security failure at its Mailchimp email marketing business allegedly led to the theft of cryptocurrency from one or more digital wallets.

In a proposed [1]class-action lawsuit [PDF] filed in federal court in northern California on Friday, the plaintiff – Alan Levinson of Illinois – claimed he and potentially others fell victim to a sophisticated phishing attack in which their Trezor cryptocurrency wallets were unlawfully accessed and funds siphoned.

Someone [2]earlier stole from Mailchimp details of Trezor's mailing-list subscribers, and used this information to reach out to those users with an email engineered to trick them into installing malware designed to hijack their digital wallets. Levinson said he believes millions of dollars in crypto-coins were stolen in this attack, including $87,000 from his own wallet.

[3]

The lawsuit accuses Intuit and Rocket Science Group – a subsidiary that operates Mailchimp – of poor security practices, allowing this alleged heist to take place.

[4]

[5]

"The hackers were able to access the Trezor email list (and likely other insensitive information) through Mailchimp and/or Intuit employee accounts," Levinson wrote in his 22-page lawsuit. "Indeed, defendants confirmed that hackers used an internal employee tool to steal data from more than 100 of their clients — with the data being used to mount phishing attacks on the users of cryptocurrency services."

It's said said Intuit "willfully, recklessly, or negligently" failed to put in place measures that would ensure people's data was protected and keep such a breach from happening, and then failed to disclose the breach in a timely manner.

[6]

Intuit [7]bought Mailchimp last fall for about $12 billion.

Getting hooked

The lawsuit states Trezor users received phishing emails on April 2 that appeared to be legitimate messages from the company claiming that their data had been compromised and their cryptocurrency was at risk of being stolen. These messages were sent to email addresses stolen from Mailchimp.

Marks were told by these bogus emails to go to what turned out to be a malicious website – suite.trẹzor.com, note the special ẹ character – to download a new version of the Trezor desktop software suite that turned out to be wallet-draining malware. According to the lawsuit, this was also made possible because an Intuit staff apparently fell victim to a phishing attack in which they inadvertently handed over their internal credentials to one or more fraudsters.

"Defendants fell victim to one of the oldest cybertricks in the book: according to reports, one of defendants' employees fell victim to a phishing email and clicked on a malicious link," the plaintiff claimed. "Accordingly, the unknown hackers were able to pilfer Trezor platform users' cryptocurrency from the compromised accounts, resulting in millions of dollars of losses."

[8]Mailchimp: Crook stole cryptocurrency clients' mailing-list subscriber info

[9]Intuit branches out into email marketing by splashing $12bn on Mailchimp acquisition

[10]FTC sues Intuit for false advertising, says 'free' TurboTax isn't always free

[11]Gootkit malware crew using SEO to get pwned websites in front of unwitting marks

The lawsuit claims the crooks were able to view about 300 Mailchimp customer accounts, and exfiltrate data, including subscriber email addresses, from 102 of them. One of the customer accounts was Trezor.

In a statement to The Register earlier this month, Mailchimp CISO Siobhan Smyth said the company's security engineers first became aware of the security breach on March 26 when a miscreant accessed a tool used by customer-facing teams for customer support and account administration. Smyth said the targeted campaign "was propagated by an external actor who conducted a successful social engineering attack on Mailchimp employees, resulting in employee credentials being compromised."

Levinson raised the March 26 date in his lawsuit, saying it was "a week before the phishing emails were sent" yet Intuit didn't raise the alarm until Trezor [12]did so when it spotted the phishing campaign.

[13]

"This lack of action was particularly concerning, as Defendants acknowledged that the hackers targeted customers in the cryptocurrency and finance sectors and that the hackers gained access to API keys for an undisclosed number of customers, allowing the attackers to send phishing emails," the lawsuit stated.

Levinson wants Intuit to pay for at least three years of credit monitoring for the victims as well as actual and punitive damages and legal fees. ®

Get our [14]Tech Resources



[1] https://regmedia.co.uk/2022/04/25/levinson_v_intuit.pdf

[2] https://www.theregister.com/2022/04/05/mailchimp_confirms_breach/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YmduaxO4CGrh1qCnMSrO4gAAABI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YmduaxO4CGrh1qCnMSrO4gAAABI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YmduaxO4CGrh1qCnMSrO4gAAABI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YmduaxO4CGrh1qCnMSrO4gAAABI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/09/14/intuit_mailchimp_acquisition/

[8] https://www.theregister.com/2022/04/05/mailchimp_confirms_breach/

[9] https://www.theregister.com/2021/09/14/intuit_mailchimp_acquisition/

[10] https://www.theregister.com/2022/03/29/ftc_tax_intuit/

[11] https://www.theregister.com/2021/03/02/gootkit_ransomware_evolution_sophos/

[12] https://twitter.com/Trezor/status/1510548489884815361

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YmduaxO4CGrh1qCnMSrO4gAAABI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



an external actor conducted a successful social engineering attack on Mailchimp employees

Howard Sway

Should have hired more experienced staff then - cos if you pay peanuts, you get monkeys.

Re: an external actor conducted a successful social engineering attack on Mailchimp employees

David 132

Whenever I hear news about Mailchimp, all I can think is "what are chimps known for? Flinging poo at all & sundry. What a very appropriate name for an email marketing company..."

At Howard Sway, re: peanuts.

ShadowSystems

I thought that if you paid in peanuts, all you could expect was an infestation of ellef, elap, effal, pacy, those big things with the tusks & the trunk? =-Jp

I'll get my coat, it's the one with the peanut-eating critters in the pockets.

Only a matter of time

Richocet

My view on cryptocurrency is that it is designed for criminal activities and also that anyone holding cryptocurrency will eventually have it stolen.

Some of the characteristics of the currency such as being decentralised and untraceable, make it the most attractive target of theft ever.

So I don't think anyone who buys crypto or uses it should be protected from theft or fraud of said crypto.

Re: Only a matter of time

David 132

There is never a bad time to remind those who haven't heard of it of the existence of [1]Web3IsGoingGreat.com .

[1] https://web3isgoinggreat.com/

leaving your wallet in a pub

iowe_iowe

Crypto and NFT's both fail the smell test for me. As someone who occasionally leaves my wallet on a pub table, the idea of putting serious personal wealth in something that is simultaneously so ephemeral, and planet-buggering, seems insane.

No house should ever be on any hill or on anything. It should be of the hill,
belonging to it.
-- Frank Lloyd Wright