Have I Been Pwned owner Troy Hunt’s mailing list compromised in phishing attack
Industry experts say the incident shows even seasoned professionals can fall victim
Troy Hunt, the security blogger behind data breach site Have I Been Pwned, has fallen victim to a phishing attack targeting his email subscriber list.
In a blog post disclosing the incident, Hunt described how the attack took place, with screen shots of the phishing email, which purported to come from his email marketing provider, Mailchimp.
The trap used a classic phishing tactic of including a button that linked to a page with a similar url to the legitimate one – mailchimp-sso.com (now deactivated) versus mailchimp.com.
Hunt, who said he was “really jet lagged and really tired” at the time entered his credentials and the one time password (OTP) and the page then hung, rather than loading.
“Moments later, the penny dropped,” Hunt wrote. “I logged onto the official website, which Mailchimp confirmed via a notification email which showed my London IP address.”
“I immediately changed my password, but not before I got an alert about my mailing list being exported from an IP address in New York,” he added.
Hunt himself and others in the industry reacting to the news have said this is an example of how hackers exploit human weaknesses to carry out successful attacks.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
In the case of Hunt, tiredness led to lack of attention, which in turn led to him falling for a phishing scam of the kind he said he would typically have recognized early.
Erich Kron, security advocate at KnowBe4, said the incident is a prime example of how even a seasoned cybersecurity veteran can fall prey to cyber criminals.
"Social engineering is largely getting the right message to the right person at the right time, and that combination can lead to unfortunate situations such as this.”
Aditi Gupta, principal security consultant at Black Duck, echoed Kron's comments, noting that bad actors deliberately "feed on fear and weaknesses such as tiredness and a sense of urgency" to bait unsuspecting users.
"This recent phishing attack further highlights that, in the end, we are all humans, and sophisticated phishing attacks could get the best of us."
Kron commended Hunt, adding that he “deserves kudos” for revealing what had happened to him and using the incident as an opportunity to educate others.
For his part, Hunt said he has gone through the usual gamut of emotions felt by someone who falls for a scam, including feeling “so stupid” and acknowledged “[his] own foolishness”.
However, he also hit out at some of Mailchimp's own practices that he claimed are poor in relation to data security. These include not offering phishing-resistant two factor authentication (2FA) and not automatically deleting unsubscribed email addresses.
Hunt concluded his blog post by offering his “sincere apologies to anyone impacted by this”, but added that “on balance I think this will do more good than harm and I encourage everyone to share this experience broadly”.
MORE FROM ITPRO
- Hackers are using this new phishing technique to bypass MFA
- 10 quick tips for identifying phishing emails
- How hackers are using legitimate tools to distribute phishing links

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
UK government calls on firms to sign Cyber Resilience Pledge as security sector boomsNews With new figures showing a boom in the country's cybersecurity sector, the government calling on businesses to make the most of the industry’s expertise
-
Two US nationals sentenced for role in prolific fake worker laptop farmsNews The Americans were raising money for the North Korean regime by allowing fake IT workers to appear as legitimate US-based employees
-
Beware of emails threatening a code of conduct reviewNews A widespread phishing campaign has targeted tens of thousands of employees
-
‘We’re not investing as much as we should in their skills and development’: Skills shortages remain a key factor in security breaches — and things could get worse with AI in the equationNews Skills capabilities remain a key factor in security breaches, according to a new study
-
‘The inbox is no longer the only frontline’: Phishing attacks are evolving as cyber criminals ramp up ‘multi-channel’ campaigns over email and Microsoft TeamsNews New research shows threat actors are ramping up “multi-channel” phishing attacks by combining lures via email and Microsoft Teams
-
Pay up or expect attrition: 77% of cyber professionals missed out on pay rises last year – and almost half now plan to switch rolesNews Organizations are overlooking cyber pros when it comes to pay increases, and it could cost them dearly
-
Tycoon 2FA is down, but not out – researchers warn the phishing as a service operation is still a huge threat to businessesNews Millions of Tycoon 2FA attacks are still hitting businesses, according to research from Barracuda
-
Zephyr Energy hackers swiped £700,000 after redirecting a contractor paymentNews Payment to a Zephyr Energy contractor was siphoned off, but the incident has been contained and new security measures implemented

