Mailshake Allegedly Breached With Internal Admin Data Claimed Exposed

A threat actor claims to have breached Mailshake, alleging the theft of a five-year analytics export containing administrator account data, subscription details, and platform activity.
Screenshot of a forum post alleging a data breach involving Mailshake. The post claims the theft of internal administrator analytics data, lists the alleged data categories and record counts, and includes a download link that has been redacted by BreachNews.
Forum post alleging a breach of Mailshake and claiming the theft of a five-year analytics export containing administrator account information, team metadata, subscription details, and platform activity.

A threat actor has claimed to have breached Mailshake, a sales engagement platform used by marketing and sales teams for email outreach and campaign automation, alleging the theft of 5 years of internal analytics data. The claims have not been independently verified.

Unlike many newly posted breach claims, the actor published what is purportedly the stolen dataset. BreachNews reviewed the archive and found a structured analytics export containing administrator account information, team metadata, subscription details, and user activity events. While the data appears internally consistent and aligns with the forum post’s description, BreachNews could not independently verify that it originated from Mailshake.

Analytics export allegedly spans five years

According to the forum post, the alleged dataset contains 229,519 analytics events collected between June 2021 and July 2026. The actor claims the archive includes information associated with approximately 538 administrator email addresses, 180 teams, nearly 4,800 device identifiers, and roughly 18,500 unique IP addresses.

BreachNews’ review found records containing administrator email addresses, administrator names, team names and identifiers, user roles, subscription status, recurring revenue values, billing terms, product identifiers, campaign counts, mailbox integration counts, feature flags, device identifiers, operating system information, IP addresses, event timestamps, and application telemetry. The archive also contains records documenting administrator activity, including signups, logins, campaign creation, purchases, team creation, session events, and other platform interactions.

Operational insights could increase risk

If authentic, the alleged dataset could provide insight into how organizations use the platform, including administrator activity, subscription status, and feature adoption. Combined with administrator contact information and device metadata, that information could increase the effectiveness of phishing or social engineering campaigns targeting customer organizations.

The forum post does not claim the dataset contains customer email campaign contents or mailbox credentials.

Latest post from same forum account

The Mailshake listing follows other alleged datasets recently published by the same forum account involving Ling App, ZoomShift, and Groomit.

No public statement from Mailshake

The forum account responsible for the post has limited posting history, and Mailshake had not issued any public statement regarding the alleged breach at the time of publication.

Although the published archive appears internally consistent and matches the categories described in the forum post, its authenticity and origin remain unverified. BreachNews will update this article if Mailshake confirms an incident or additional evidence emerges.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site