Skip to main content

Even the most seasoned security experts can fall prey to phishing scams, as Troy Hunt, the renowned creator of HaveIBeenPwned, recently revealed in a candid post. Hunt, who has spent years helping millions check if their personal data has been compromised in breaches, became the victim of a phishing attack targeting his Mailchimp account.

The incident began when Hunt was traveling and jet-lagged, a reminder that human vulnerability often aligns with moments of fatigue or distraction. The attacker sent a cleverly disguised email designed to look urgent and legitimate. Despite multiple warning signs—such as an inauthentic sender address, false urgency in the message, and the absence of autofill triggers from Hunt’s password manager—the fatigue clouded his usual vigilance. The result: the attacker captured his login credentials and exported the entire email list of roughly 16,000 subscribers, including those who had unsubscribed.

This breach highlights several critical lessons for everyone. First, phishing emails often carry telltale signals, but these can easily be overlooked, especially when we’re tired or stressed. Hunt emphasizes the importance of never clicking on urgent email links directly. Instead, always access your accounts through official channels or verified URLs. For phone calls, use numbers printed on official statements or verify the contact through trusted online searches.

Furthermore, Hunt advocates for modern security measures like passkeys, which are inherently resistant to phishing attacks, as well as stronger two-factor authentication (2FA) options such as hardware security keys like Yubikeys or Google’s Titan Security Key. These tools provide an added layer of defense that can prevent credential theft even if a phishing attempt seems convincing.

Another eye-opening takeaway concerns data retention. Many users assume that unsubscribing or leaving a service deletes their information, but Hunt’s experience reveals otherwise. Mailchimp retains email addresses of unsubscribers to prevent them from being re-added without consent, meaning your data might remain exposed even after you think you’re “gone.” It’s a stark reminder that to truly erase your digital footprint, you often have to actively request data deletion, which is a right under various privacy laws.

For most everyday accounts, Hunt suggests employing email masking services that generate unique email aliases per service. This way, if one service is compromised, the leak can’t easily be correlated with your other accounts, significantly reducing the risk of broad profiling by attackers.

Ultimately, this incident serves as a powerful reminder: phishing can happen to anyone, regardless of expertise. The key isn’t to expect perfection but to build habits and systems that protect you even when your guard is down. Hunt’s transparency in sharing his experience is a valuable lesson for all of us striving to navigate the increasingly complex landscape of digital security.