Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 10, 2026 at 6:30 UTC, Brevo, an email marketing provider, identified a compromise that exposed 138 corporate accounts. The attacker exploited a vulnerability in how the platform handles SAML SSO authentication, gaining sufficient access to send phishing emails from legitimate domains of crypto companies and exfiltrate contact lists for future attacks. The incident does not affect the direct systems of the targeted victims, but their most trusted communication channel.
- 138 Brevo accounts compromised via exploit of a vulnerability in the platform's SAML SSO implementation.
- 6 accounts used to send phishing emails to stored contacts; 43 accounts had contacts exported.
- Emails with specific subjects — "Critical Security Alert: STM32 Entropy Bug Identified" for Trezor, "Data Breach Notice: Please refresh API Keys as soon as possible" for CoinTracking — sent from legitimate domains.
- Trezor confirmed the third-party provider compromise and disabled the domain used for phishing.
How the attack works: SAML exploit and corporate domain trust
According to Brevo's postmortem reported by Malwarebytes, the attacker identified a vulnerability in the platform's SAML-based Single Sign-On mechanism. SAML (Security Assertion Markup Language) is a standard protocol for exchanging authentication data between identity providers and service providers; when its implementation is flawed, it can enable privilege escalation or unauthorized access to multiple resources.
The dossier does not specify which exact component of the SAML implementation was vulnerable — whether an internal configuration, an identity provider vendor, or another variant — nor whether the exploit required a zero-day vulnerability or leveraged a known weakness. What is documented is the outcome: access to 138 accounts, with varying levels of subsequent activity.
The distinguishing feature of the attack lies in the use of legitimate corporate domains. The emails sent lacked classic phishing indicators: no typosquatted domains, no obvious spelling errors, no suspicious senders. The Record cites user testimonies that perceived them as authentic communications precisely because they originated from the companies' official channels. This neutralizes the user's primary psychological defense mechanism: intuitive verification of sender legitimacy.
Trezor, CoinTracking, BitBox: the phishing emails and reactions
Among the companies whose customers received phishing emails, sources confirm Trezor, CoinTracking, and BitBox. The exact subjects, reported by Malwarebytes, reveal a social engineering strategy calibrated for a crypto audience: for Trezor, a fake hardware vulnerability ("Critical Security Alert: STM32 Entropy Bug Identified"); for CoinTracking, a bogus data breach notice requesting API key updates.
Trezor reacted through its social channels with a message that, quoted by The Record, explicitly states the nature of the problem: "Do not click on any link. We have taken down the domain, and we are investigating the situation, including how the hackers got access to our legit domain." The phrasing is significant: Trezor acknowledges that the domain used was "legitimate," not spoofed, confirming that the compromise affected the distribution channel rather than the company's proprietary infrastructure.
The dossier does not document similar reactions from CoinTracking or BitBox, nor does it specify whether other companies beyond these three were involved.
The numbers of the compromise: impact distribution
Quantitative data, drawn from the Brevo postmortem as reported by Malwarebytes, shows a precise breakdown of the 138 compromised accounts:
"On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts. 6 of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts they exported the contacts. 93 accounts have no meaningful activity." — Brevo postmortem, reported by Malwarebytes
Brevo initially communicated 120 compromised accounts, then corrected to 138 in the final postmortem. The 93 accounts "with no meaningful activity" do not equal 93 accounts not accessed: the source specifies absence of activity, not absence of intrusion. Contacts exported from 43 accounts represent a data reservoir for future attacks, although the dossier does not confirm those lists have already been used.
The number of victims who actually interacted with the phishing emails is not quantified by sources. Likewise, the identity of the attacker or a responsible threat actor group does not emerge from the available material.
Why this matters
The brief does not document specific remedial measures available to users or Brevo client companies beyond the platform's general statement. According to the cited source, Brevo indicated it removed the attacker from the system and deployed a permanent fix, but does not specify the patch's technical content nor rollout timelines.
The dossier does not list operational recommendations for phishing email recipients nor guidelines for verifying the authenticity of future communications. The source does not specify whether Brevo individually notified the 138 account holders or the exposed contacts.
The incident raises questions unanswerable from available sources: whether the nature of the SAML exploit is configurational or a structural vulnerability, whether periodic security audits could have detected the weakness, whether other email marketing providers share similar SAML implementations.
For the crypto sector, the case highlights a structural contradiction. Companies invest in hardware security and fund custody, but delegate their most sensitive communication channel — the one through which they route alerts, updates, verifications — to third parties. When that channel is compromised, the user's perimeter defense — recognizing phishing — dissolves because the attack arrives from the perimeter considered safe.
Information is based on the cited advisory and current as of publication.
Sources
- https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach
- https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.