2022 HubSpot — targeted account compromise focused on cryptocurrency industry customers
Data compromised
Customer relationship metadata accessible within the compromised employee context—primarily business contact fields (per HubSpot/press summaries)
Technical writeup
HubSpot disclosed a bad actor compromised a HubSpot employee account and used it to target customers in the cryptocurrency industry, exporting limited contact and business information available within the compromised portal workflows.
Root cause
Employee account takeover through reported illicit means (per HubSpot disclosure summarized by press)