2022 Klaviyo — phishing-led employee account compromise; crypto-customer marketing lists exfiltrated
Data compromised
Marketing list fields for targeted crypto-related customer accounts per Klaviyo
Technical writeup
Klaviyo stated attackers phished employee credentials and exported marketing-list data for a focused set of cryptocurrency-industry customers; the company forced rotations and published an incident blog.
Root cause
Phishing leading to employee session/account compromise