PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Creator of HaveIBeenPwned Data Breach Site Falls for Phishing Email

However, the hacker behind the phishing attack appears to have only stolen the email addresses of those who subscribed to Troy Hunt's blog, rather than Haveibeenpwned.com.

 & Michael Kan Principal Reporter

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS
(Sarayut Thaneerat via Getty)

A hacker has managed to phish Troy Hunt, the creator of HaveIBeenPwned.com, tricking the security expert into clicking a malicious email while he was jetlagged. 

The breach affects people who subscribed to Hunt’s personal blog, rather than HaveIBeenPwned, a data breach notification site that’s attracted millions of users. “I'm enormously frustrated with myself for having fallen for this, and I apologize to anyone on that list,” he said. 

On Tuesday, Hunt disclosed the breach, which affects 16,000 email addresses. The attack  occurred through a phishing message that pretended to come from his email provider Mailchimp. The phishing email claimed that Mailchimp had received a spam complaint and was forced to restrict “sending privileges” to Hunt’s account tied to his personal blog. 

Hunt clicked on the phishing email, which led him to enter his credentials and one-time passcode into a hacker-controlled login page. But he quickly realized something was off when the login process “hung.” Hunt changed his password to his real Mailchimp account, but it was too late: The hacker had breached his account, and exported his mailing list — suggesting the entire attack was automated. 

Hunt adds that 7,535 users that had unsubscribed to his blog were also ensnared in the hack due to Mailchimp failing to delete their emails. 

Hunt, who’s Australian, says he fell for the phishing scheme while visiting government partners in London. Although he’s received and fended off a “gazillion similar phishes before,” Hunt said this particular phishing email caught him off guard because he was exhausted from traveling.

“Tiredness, was a major factor. I wasn't alert enough, and I didn't properly think through what I was doing,” he wrote on his own blog. "The attacker had no way of knowing that (I don't have any reason to suspect this was targeted specifically at me), but we all have moments of weakness and if the phish times just perfectly with that, well, here we are.”

The malicious email
(Credit: Troy Hunt)

Like other phishing scams, the malicious email successfully created a sense of urgency and exploited Hunt’s fears by fooling him into thinking Mailchimp was about to suspend his newsletter. “It wasn't all bells and whistles about something terrible happening if I didn't take immediate action. It created just the right amount of urgency without being over the top,” he said. 

The hack also underscores how two-factor authentication isn’t bulletproof. Hunt’s Mailchimp account had 2FA activated, but the phishing attack was still able to trick him into giving up a one-time passcode, which it quickly used to break into his account. “Let this be a lesson as to how completely useless it is against an automated phishing attack that can simply relay the OTP as soon as it's entered,” he said. 

In response, he’s asked Mailchimp about whether the company plans on offering passkeys, which can stop such phishing attacks. He’s also wondering why Mailchimp didn’t delete the email addresses of people who unsubscribed to his blog.   

In the meantime, Hunt is notifying affected users through email. Mailchimp didn’t immediately respond to a request for comment

About Our Expert

Michael Kan

Michael Kan

Principal Reporter

My Experience

I've been a journalist for over 15 years. I got my start as a schools and cities reporter in Kansas City and joined PCMag in 2017, where I cover satellite internet services, cybersecurity, PC hardware, and more. I'm currently based in San Francisco, but previously spent over five years in China, covering the country's technology sector.

Since 2020, I've covered the launch and explosive growth of SpaceX's Starlink satellite internet service, writing 600+ stories on availability and feature launches, but also the regulatory battles over the expansion of satellite constellations, fights with rival providers like AST SpaceMobile and Amazon, and the effort to expand into satellite-based mobile service. I've combed through FCC filings for the latest news and driven to remote corners of California to test Starlink's cellular service.

I also cover cyber threats, from ransomware gangs to the emergence of AI-based malware. In 2024 and 2025, the FTC forced Avast to pay consumers $16.5 million for secretly harvesting and selling their personal information to third-party clients, as revealed in my joint investigation with Motherboard.

I also cover the PC graphics card market. Pandemic-era shortages led me to camp out in front of a Best Buy to get an RTX 3000. I'm now following how the AI-driven memory shortage is impacting the entire consumer electronics market. I'm always eager to learn more, so please jump in the comments with feedback and send me tips.

The Best Tech I've Had:

  • My first video game console: a Nintendo Famicom
  • I loved my Sega Saturn despite PlayStation's popularity.
  • The iPod Video I received as a gift in college
  • Xbox 360 FTW
  • The Galaxy Nexus was the first smartphone I was proud to own.
  • The PC desktop I built in 2013, which still works to this day.

Read full bio