All Vendors
marketing_automation

Mailchimp

Mailchimp triggers 9 BTI behavioral codes — the most of any vendor in this group — revealing a full tracking stack hiding behind what most organizations treat as a simple email marketing tool.

148 IOCs2 detections50% pre-consent2 sites
90
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Mailchimp discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

2 detections across 2 sites50% pre-consent activity
CRITICAL

Pre-Consent Activity

Mailchimp was observed loading and executing before user consent was obtained on 50% of sites where it was detected.

GDPRePrivacy
HIGH

Pending Analysis

9 BTI behavioral codes detected across 2 detections on 2 sites. Full claims extraction required for gap analysis.

Disclosure Gaps

Claims vs. Observed Behavior

1 gaps
1 HIGH

Pending Analysis

HIGH
They Claim

Claims analysis pending

Observed Behavior

9 BTI behavioral codes detected across 2 detections on 2 sites. Full claims extraction required for gap analysis.

Customer Impact

What This Means For You

If Mailchimp is deployed on your site — even as a simple email signup form — your visitors are exposed to 9 distinct behavioral tracking codes. Your privacy notice likely describes Mailchimp as an email marketing processor, but runtime analysis reveals session recording, fingerprinting, and identity resolution capabilities that constitute a fundamentally different processing activity. Under GDPR, each undisclosed processing purpose is a separate transparency violation. The Intuit ownership means your visitor data enters a financial data conglomerate's ecosystem — a data controller relationship that almost certainly is not reflected in your DPIA or Records of Processing Activities. Half your visitors encounter this tracking before consent, creating systematic legal exposure.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Mailchimp

  • Audit every Mailchimp embed on your properties — forms, pop-ups, landing pages — each one deploys the full behavioral tracking stack
  • Review your ROPA and DPIA entries for Mailchimp — verify they reflect session recording, fingerprinting, and identity resolution, not just email processing
  • Test pre-consent behavior: verify whether Mailchimp embeds fire before your CMP grants consent
  • Review the Intuit/Mailchimp DPA for data sharing provisions across Intuit subsidiaries

If You're Evaluating Mailchimp

  • Assess whether email marketing functionality can be achieved without embedding Mailchimp JavaScript on-site (server-side API integration)
  • Request explicit confirmation from Mailchimp on what behavioral data is collected via on-site embeds vs. email-only functionality
  • Evaluate the Intuit controller relationship and whether it requires separate privacy notice disclosure
  • Consider whether 9 BTI codes on an email marketing tool is proportionate to the business value delivered

Negotiation Leverage

  • 9 BTI behavioral codes — the highest count in this analysis group — on what most organizations classify as a simple email marketing tool
  • Intuit ownership (2021, $12B acquisition) means your visitor behavioral data enters a financial data conglomerate ecosystem — demand clarity on cross-subsidiary data sharing
  • 50% pre-consent firing rate with session recording and fingerprinting creates GDPR Article 5(1)(a) exposure that email consent does not cover
  • Most organizations' DPIAs classify Mailchimp as an email processor — the runtime reality of 9 behavioral codes requires reclassification and re-assessment
  • Request server-side API integration as an alternative to JavaScript embeds to eliminate on-site behavioral tracking entirely
Runtime Detections

Runtime Detections

9 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

Impact: Mailchimp deploys evasion infrastructure that may alter behavior during compliance audits, meaning your testing environment may not reveal the full scope of data collection.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Keystroke and mouse tracking on email signup forms means Mailchimp captures behavioral patterns from every visitor who interacts with — or even hovers near — a Mailchimp-powered component on your site.

BTI-C07Session Recording

Full session replay

Impact: Session replay capability embedded in what most organizations consider a simple email widget. Visitors interacting with signup forms are being recorded in ways your privacy notice almost certainly does not disclose.

BTI-C08Cross-Domain Sync

Identity stitching

Impact: Identity stitching across domains means Mailchimp can correlate your visitors with their activity on other Mailchimp-embedded sites, building cross-site behavioral profiles within Intuit's data infrastructure.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: 50% pre-consent firing rate means half your visitors encounter Mailchimp's full behavioral tracking stack before they can express consent preferences. Email signup consent does not cover session recording or fingerprinting.

BTI-C10Fingerprinting

Device identification

Impact: Device fingerprinting on an email marketing embed creates persistent identification that survives cookie clearing, allowing Mailchimp to recognize visitors even after they attempt to reset tracking.

BTI-C13Persistence Mechanisms

Long-lived identifiers

Impact: Long-lived identifiers with 5 cookies deployed ensure Mailchimp maintains visitor recognition across sessions. Combined with identity resolution, this creates durable profiles tied to real individuals.

BTI-C14Identity Resolution

PII deanonymization

Impact: PII deanonymization means Mailchimp can connect anonymous browsing behavior to identifiable email subscribers. This data flows to Intuit, creating a controller relationship most organizations have not assessed.

BTI-C15Tag Manager

Container/loader (neutral)

Impact: Mailchimp operates as a container/loader, potentially introducing additional tracking capabilities beyond what the initial embed appears to provide.

IOC Manifest

IOC Manifest

146 INDICATORS

Indicators of compromise across 5 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*mailchimp.com/release/dist/js-src/ecs/cookie-preferences-manager.*.js*
Tracking script
TRACK
*mailchimp.com/release/plums/cxp/js/experiment-loader.*.1.js*
Tracking script
TRACK
*mailchimp.com/KmxH5_/A7Yg/iZWkq/2ed/iJf2GT/3Q7SzVtctfp6bh/OBoxAQ/Wyl/rSTtMAjUB*
Tracking script
TRACK
*mailchimp.com/ex.js*
Tracking script
TRACK
*mailchimp.com/release/plums/cxp/js/index.*.1.js*
Tracking script
TRACK
*mailchimp.com/metrics/*
Tracking script
TRACK
*mailchimp.com/release/plums/chunks/js/*.*.1.js*
Tracking script
TRACK
*mailchimp.com/release/plums/chunks/js/617.*.1.js*
Tracking script
TRACK
*mailchimp.com/metrics/gtd*
Tracking script
TRACK
chimpstatic.com
Tracking script
TRACK
mailchimp.com/release/dist/js-src/ecs/cookie-preferences-manager.20fc3264ba1c0834.js
Auto-extracted from scan
TRACK
mailchimp.com/ex.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/cxp/js/experiment-loader.64bd38a2.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/cxp/js/index.de18ee25.1.js
Auto-extracted from scan
TRACK
mailchimp.com/KmxH5_/A7Yg/iZWkq/2ed/iJf2GT/3Q7SzVtctfp6bh/OBoxAQ/Wyl/rSTtMAjUB
Auto-extracted from scan
TRACK
mailchimp.com/metrics/
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/7163.0be4fee25eeb10fc.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/9692.5fd8addeb32b7018.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/4798.44de04f70dbf68e9.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/1103.a7ef8e7f02915754.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/6195.d8aa2f22ecbba490.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/7100.ef91c965850b1813.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/7385.ea7d56a8115efcc9.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/2362.49d5f9e21a4f8705.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/6482.b4fbaabc5a4fb1ed.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/5851.af934b4f5f153612.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/7707.5c1c08d1bdc89de5.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/7746.ff2589b4a1b56551.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/2845.00d9bd16c76a9912.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/7985.15c829ecb4203d13.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/7941.d3757bad058d684b.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/6773.f3470a2b0b4f7b81.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/9867.c175b776b69f222b.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/5411.4d61f423ab4cda5b.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/617.0c5aa92fbc89b3e1.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/4524.c7036e26ebe530c0.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/7426.4f4affcdad71ab90.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/9805.18008f3815e9d674.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/4073.14af7fcbcba4a625.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/9542.6cf9ebb46cdaa64a.1.js
Auto-extracted from scan
TRACK
mailchimp.com/release/plums/chunks/js/3156.7c4d6a62ecfc710d.1.js
Auto-extracted from scan
TRACK
mailchimp.com/metrics/gtd
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Mailchimp was acquired by Intuit in September 2021 for $12 billion, joining a portfolio that includes TurboTax, QuickBooks, and Credit Karma. This positions Mailchimp's behavioral data within one of the largest financial data ecosystems in the United States. Mailchimp integrates with hundreds of platforms including Shopify, WordPress, Salesforce, and virtually every major CMS and e-commerce platform. Its ubiquitous embed presence — signup forms, pop-ups, landing pages — means Mailchimp JavaScript runs on millions of sites, creating an enormous cross-domain observation network under Intuit's control.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

148 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details