The creator of the HaveIBeenPwned website, Troy Hunt, fell victim to a phishing attack.
Hunt received an email supposedly from Mailchimp, leading him to a fake Mailchimp domain.
The phishing attack compromised Hunt's personal Mailchimp account and resulted in the theft of approximately 16,000 records.
Lessons learned from this incident include being cautious of emails creating a sense of urgency and considering the circumvention of password managers as a potential sign of a spoofed domain.