Invest1 publisher3 min readPublished
One SAML flaw let an attacker export the contact lists of 43 Brevo customers
Brevo closed the SAML vector and reset active sessions by about 8:30 UTC on 10 September. Six of the 138 breached accounts sent phishing mail, and Trezor counted roughly 347,000 recipients in a single day.
The Investor · Invest desk

What happened
- An attacker exploited a flaw in Brevo's SAML SSO handling on 9 and 10 September 2026. That gave unauthorized access to 138 customer accounts on the email marketing platform formerly known as Sendinblue.
- Six of those accounts were used to send phishing emails directly to the subscribers of the companies that owned them.
- A further 43 accounts had their contact lists exported, so subscriber addresses left the platform even where no phishing message followed immediately.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure The phishing arrived under the senders' own branding. The support load and the subscriber trust are charged to Trezor, BitBox and CoinTracking; the authentication that failed was the platform's.
- constraint No vendor can announce a completion date for the 43 exported lists. An email address cannot be rotated the way a password can, and stays valid for as long as the subscriber keeps it.
- decision Any company whose roster sits inside a hosted sender now has to choose: accept a vendor's SSO configuration as part of its own perimeter, or pay to run sending itself. Neither option comes with a comparative failure rate to price it.
Six accounts sent mail. Forty-three gave up their contact lists, and those lists stay exported after the incident response stops the sending.
Of the 138 accounts the attacker reached [2], six, or 4.3%, were used to send phishing to subscribers [3][13], and 43, or 31%, had their contact lists exported [4][14]. If none of those overlap, 49 accounts were put to some use and 89 were entered with nothing further reported [15]. Brevo closed the vector and reset active sessions by about 8:30 UTC on 10 September [5]. Those resets ended the attacker's access to the accounts; they did not recover the 43 lists.
Trezor said phishing email reached roughly 347,000 of its newsletter subscribers on 9 September [6]. That is the disclosed reach of one of the six sending accounts [18]. BitBox and CoinTracking confirmed their Brevo accounts were among those exploited [7]. Nothing in the incident touched wallets or private keys; the input was exported contact data [9].
The mail used accurate branding and manufactured urgency around a security problem that did not exist [10]. The warnings spread past the breached accounts. Solana Mobile, whose account does not appear to have been among the 138, told its own users to expect phishing attempts [8].
A subscriber roster is one of the few assets a company cannot re-issue after a loss. Credentials rotate. An email address on an exported list stays valid for as long as the subscriber keeps it, and that is why Crypto Briefing describes lists built over years of legitimate marketing as attack infrastructure once they move [16]. In my view the durable liability sits with the 43 more than the six, and the disclosure a customer actually needs is whether it was one of them. The published account names none of the 43 and gives no total customer count for Brevo, so the share of the platform's base that was reached is unknown [17].
This is where a customer's own controls were never in play. A flaw in how SAML assertions are handled or verified can let an outsider forge or hijack an authentication token and get in without a password at all [11]. Crypto Briefing's argument is that this is structural, that a company can secure its systems, tighten access control and train staff and still be exposed by a vendor's authentication layer [12]. The counter-argument is that bringing sending in-house relocates the same authentication surface into your own estate, and there is nothing in this record to compare the two arrangements against.
If the 43 exported lists never produce a second wave, the event was one day of impersonated mail to a known population, and the six sending accounts were the whole of it. The account stops at 9 September [6].
What to watch
- Whether any of the 43 exported lists surface in a second phishing wave after 9 September. That sets the duration of the loss.
- Whether Brevo names the 43 affected customers or publishes its total customer count. The breach share cannot be calculated until it does.
- Whether Trezor, BitBox or CoinTracking move sending off the platform or seek recovery under their vendor contracts.