← ActiveCampaign

2022 ActiveCampaign — social engineering; unauthorized exports from some customer accounts

2022 Unknown records affected Share on X

Data compromised

Marketing subscriber PII and engagement metadata in impacted customer tenants

Technical writeup

ActiveCampaign customers including BitBox and Unchained publicly reported that a social-engineering campaign against the vendor allowed attackers to access certain marketing-automation accounts and export contact lists and related subscriber metadata (names, emails, IP addresses, and newsletter interaction context). The incident was characterized as account-level export abuse rather than a wholesale platform database raid, but it materially exposed end-user and prospect PII held in SaaS workspaces.

Root cause

Social engineering leading to account takeover and bulk export of list data

References