Brevo
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·24TfuE…JRMeSummary
Brevo (formerly Sendinblue) is a Paris-based email marketing and CRM platform serving over 600,000 customers globally. On September 10, 2026, an attacker exploited a critical authorization boundary flaw in Brevo's SAML SSO implementation to compromise 138 customer accounts, six of which were used to send phishing emails to hundreds of thousands of cryptocurrency users. The incident is a confirmed supply-chain risk event, with Brevo having issued a public post-mortem acknowledging the flaw and deploying a fix.
Connected Entities
1 entitiesTimeline(8 events)
1 January 2023
Sendinblue rebrands to Brevo, reflecting expansion into CRM, SMS, and CDP services.
Omnisend Brevo review10 September 2026
At approximately 06:30 UTC, Brevo's security team detects unauthorized access to customer accounts via a SAML SSO authorization boundary flaw. Attacker had created a rogue SSO configuration and invited legitimate Brevo customers into it, gaining cross-organization access without their passwords.
Brevo official incident post-mortem10 September 2026
Phishing emails begin reaching subscribers of affected Brevo customers, including approximately 347,000 Trezor newsletter subscribers. Subject lines include 'Critical Security Alert: STM32 Entropy Vulnerability' (Trezor) and 'Data Breach Notice: Please refresh API Keys as soon as possible' (CoinTracking).
SecurityWeek10 September 2026
Trezor detects the phishing campaign and disables the malicious domain at the DNS level within approximately 20 minutes of detection. Approximately 2,500 recipients had already clicked the malicious link before takedown.
Trezor official blog10 September 2026
Brevo closes the SAML SSO attack vector and force-logs all active sessions by approximately 08:30 UTC (11:30 AM CEST), approximately two hours after initial detection.
Brevo official incident post-mortem10 September 2026
Brevo publishes a full post-mortem confirming 138 accounts were compromised (6 used for phishing campaigns, 43 had contacts exported, 93 with no meaningful activity), acknowledges the flaw, and states a legal complaint was filed.
Brevo official incident post-mortem11 September 2026
Trezor, BitBox, CoinTracking, and Solana Mobile publicly warn their users of the phishing incident. SecurityWeek, CoinTelegraph, Crypto Briefing, BleepingComputer, and Malwarebytes report on the breach.
SecurityWeekDecision Log
- hash: 3XXKRs4EKuUw5gN1eS5voWE85XgG45Se7hqUropXwNF3
This investigation is cryptographically anchored to the Solana blockchain (1 event). 6 of 8 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 9/12/2026, 5:35:42 PM
last updated: 9/12/2026, 8:47:21 PM
avoid.net — verified advice for a post-truth world