2022 ActiveCampaign — social engineering; unauthorized exports from some customer accounts
Data compromised
Marketing subscriber PII and engagement metadata in impacted customer tenants
Technical writeup
ActiveCampaign customers including BitBox and Unchained publicly reported that a social-engineering campaign against the vendor allowed attackers to access certain marketing-automation accounts and export contact lists and related subscriber metadata (names, emails, IP addresses, and newsletter interaction context). The incident was characterized as account-level export abuse rather than a wholesale platform database raid, but it materially exposed end-user and prospect PII held in SaaS workspaces.
Root cause
Social engineering leading to account takeover and bulk export of list data