Skip to main content
AVOID.NET

Brevo

avoid.net/brevo42/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·24TfuE…JRMe

Summary

Brevo (formerly Sendinblue) is a Paris-based email marketing and CRM platform serving over 600,000 customers globally. On September 10, 2026, an attacker exploited a critical authorization boundary flaw in Brevo's SAML SSO implementation to compromise 138 customer accounts, six of which were used to send phishing emails to hundreds of thousands of cryptocurrency users. The incident is a confirmed supply-chain risk event, with Brevo having issued a public post-mortem acknowledging the flaw and deploying a fix.

Connected Entities

1 entities
Organizations
Brevo
Relationships
    Have evidence about Brevo?

    Timeline(8 events)

    1 January 2012

    Brevo founded in Paris, France as Sendinblue by Armand Thiberge.

    Omnisend Brevo review

    1 January 2023

    Sendinblue rebrands to Brevo, reflecting expansion into CRM, SMS, and CDP services.

    Omnisend Brevo review

    10 September 2026

    At approximately 06:30 UTC, Brevo's security team detects unauthorized access to customer accounts via a SAML SSO authorization boundary flaw. Attacker had created a rogue SSO configuration and invited legitimate Brevo customers into it, gaining cross-organization access without their passwords.

    Brevo official incident post-mortem

    10 September 2026

    Phishing emails begin reaching subscribers of affected Brevo customers, including approximately 347,000 Trezor newsletter subscribers. Subject lines include 'Critical Security Alert: STM32 Entropy Vulnerability' (Trezor) and 'Data Breach Notice: Please refresh API Keys as soon as possible' (CoinTracking).

    SecurityWeek

    10 September 2026

    Trezor detects the phishing campaign and disables the malicious domain at the DNS level within approximately 20 minutes of detection. Approximately 2,500 recipients had already clicked the malicious link before takedown.

    Trezor official blog

    10 September 2026

    Brevo closes the SAML SSO attack vector and force-logs all active sessions by approximately 08:30 UTC (11:30 AM CEST), approximately two hours after initial detection.

    Brevo official incident post-mortem

    10 September 2026

    Brevo publishes a full post-mortem confirming 138 accounts were compromised (6 used for phishing campaigns, 43 had contacts exported, 93 with no meaningful activity), acknowledges the flaw, and states a legal complaint was filed.

    Brevo official incident post-mortem

    11 September 2026

    Trezor, BitBox, CoinTracking, and Solana Mobile publicly warn their users of the phishing incident. SecurityWeek, CoinTelegraph, Crypto Briefing, BleepingComputer, and Malwarebytes report on the breach.

    SecurityWeek
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event). 6 of 8 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 9/12/2026, 5:35:42 PM

    last updated: 9/12/2026, 8:47:21 PM

    avoid.net — verified advice for a post-truth world