Brevo Email Platform Breach Sparks Phishing Warnings Across Crypto Industry
A security flaw in the SAML single sign-on system used by email marketing platform Brevo (formerly Sendinblue) allowed an attacker to gain unauthorized access to 138 customer accounts over September 9-10, 2026. Six of those accounts were used to send phishing emails directly to subscribers, while 43 others had their contact lists exported, meaning customer email addresses were exposed even where no phishing message was sent immediately. Brevo detected the intrusion and closed off access by resetting active sessions the following morning.
The crypto industry was hit hardest. Hardware wallet maker Trezor confirmed phishing emails reached around 347,000 of its newsletter subscribers, and BitBox and CoinTracking also confirmed their Brevo accounts were compromised. The phishing messages used a common tactic: impersonating a trusted brand and creating a false sense of urgency to trick recipients into clicking malicious links or entering credentials. The attackers relied on stolen contact data rather than any direct compromise of wallets or private keys.
Solana Mobile, whose own account does not appear to have been among those breached, issued a public warning to its users about the elevated phishing risk following the incident, given how widely the exposure spread across crypto-related companies using the same email platform.