Mandrill
We noticed an unusual surge in credential stuffing attempts targeting accounts associated with transactional email services in late June 2025. This pattern, while not entirely novel, escalated in volume and sophistication, prompting a deeper investigation into the underlying infrastructure. What struck us was the specific targeting of users who also maintained active Mandrill accounts, suggesting a correlation beyond mere coincidence. The subsequent discovery of a substantial data leak originating from Mandrill confirmed our suspicions and highlighted a significant exposure of sensitive customer information.
The Mandrill breach, discovered on June 27, 2025, involved a database compromise that exposed a considerable volume of customer data. A total of 463,769 unique email addresses and associated phone numbers were exfiltrated. Beyond contact information, the leak also included company names, physical addresses, and URLs pointing to social media profiles. This data, totaling over 943,000 records in its entirety, was subsequently disseminated on a prominent hacking forum, increasing the immediate risk of further exploitation. The nature of the exposed data suggests a potential for targeted phishing campaigns, business impersonation, and further credential compromise through social engineering tactics. The source structure of the leak indicates a direct database extraction, bypassing typical application-level security controls.
While direct news coverage of the Mandrill breach itself was limited at the time of discovery, the incident aligns with broader trends in the cybersecurity landscape. Open-source intelligence (OSINT) has indicated a rise in attacks targeting SaaS providers and their integrations, as these often serve as a gateway to larger customer bases. Research from firms like Mandiant has consistently highlighted the value threat actors place on aggregated contact and company information for business-to-business (B2B) targeting. The posting of this data on a well-known hacking forum suggests it will likely be leveraged in subsequent attacks, potentially impacting organizations that rely on Mandrill for their transactional email needs.
Breach Breakdown
463,769 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds