Digital marketing platform Mailer Lite issued an email alert stating that a support team member clicked on a phishing link, entered Google credentials and performed a secondary confirmation, allowing hackers to gain access to Mailer Lite's internal systems.
After gaining access, the attackers performed password resets for specific users on the admin panel, further solidifying their unauthorized control. The attackers impersonated user accounts and focused entirely on cryptocurrency-related accounts. The attackers accessed 117 accounts, and a small number of accounts were used to launch phishing campaigns using personal information.
According to Mailer Lite, the system did not send any emails, nor did it export its contact list. (Decrypt)
Earlier today, Blockaid reported that Mailer Lite suffered a phishing attack, resulting in a loss of more than $600,000.