After years of providing breach notifications and useful advice about how to avoid getting hacked, Have I Been Pwned operator Troy Hunt’s personal blog mailing list has become the source of a breach after he fell for a fake spam alert phishing attack this week. He has notified subscribers, and is following up for people who unsubscribed but still had data stored by his provider, Mailchimp.
Read the blog post for details on how they got him (listen to your password manager), how it could’ve been avoided (passkeys!), and what else there is to learn.









