Email marketing platforms are the quiet infrastructure of the internet, the unglamorous pipes that move newsletters and alerts from companies to inboxes. A breach at Brevo, the email marketing service formerly known as Sendinblue, exposed a vulnerability that sent ripples across the crypto industry, prompting Solana Mobile to warn its users about elevated phishing risks.
The breach unfolded on September 9-10, 2026, when an attacker exploited a flaw in Brevo’s SAML SSO handling, a single-sign-on authentication mechanism that, when misconfigured or vulnerable, can hand an outsider the keys to a remarkably wide door.
What actually happened
The attacker gained unauthorized access to 138 Brevo customer accounts using the SSO vulnerability. Of those, six accounts were weaponized to send phishing emails directly to subscribers. Another 43 accounts had their contact lists exported, meaning email addresses quietly left the building even if no phishing message followed immediately.
Brevo identified the intrusion and closed the attack vector by approximately 8:30 AM UTC on September 10, resetting active sessions to cut off further unauthorized access.
The crypto sector bore the brunt of the targeting. Trezor, the hardware wallet maker, disclosed that phishing emails reached roughly 347,000 of its newsletter subscribers on September 9. BitBox and CoinTracking also confirmed their Brevo accounts were among those exploited, with their user bases receiving similar impersonation attempts.
The phishing campaigns leaned on a familiar playbook: impersonate a trusted brand, manufacture urgency around a fabricated security issue, and push the recipient toward a malicious link or credential-harvesting page. The raw material for these attacks was the exported contact data, not a direct compromise of wallets or private keys.
Solana Mobile issued a warning to its users flagging the phishing risk in the wake of the incident. The company’s own account does not appear to have been among the 138 compromised, but the broader exposure across crypto-adjacent firms was enough to warrant a public heads-up to anyone who might receive suspicious emails claiming to be from the brand.
Why crypto companies keep ending up here
Third-party email platforms create a structural risk that individual companies can do little to fully control. A company can secure its own systems, implement rigorous access controls, and train its staff, and still find itself exposed because a vendor somewhere upstream had a misconfigured authentication layer.
The SAML SSO vulnerability at the center of this breach is worth understanding briefly. SAML, which stands for Security Assertion Markup Language, is the technology that lets you log into a third-party service using credentials from another provider. When a vulnerability exists in how the assertions are handled or verified, an attacker can potentially forge or hijack authentication tokens, gaining access without needing a password at all.
What users and companies should do now
The immediate risk for anyone subscribed to a crypto-related newsletter, whether from Trezor, BitBox, CoinTracking, Solana Mobile, or any other brand using Brevo, is a heightened volume of convincing phishing attempts. The emails will likely reference real products, use accurate branding, and create pressure around urgent security scenarios.
The core defense is skepticism about unsolicited emails asking for any action, particularly clicking links, entering credentials, or confirming seed phrases. No legitimate crypto company will ask for a seed phrase over email. Ever.
For companies, the incident highlights a due diligence gap that has become increasingly costly. Vetting third-party vendors for security posture, specifically their authentication infrastructure and incident response capabilities, is no longer optional for businesses operating in high-value target sectors.
Trezor’s exposure of 347,000 subscriber addresses in a single incident gives a sense of scale. Contact lists built over years of legitimate marketing become attack infrastructure when they fall into the wrong hands, no wallet compromise required.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
23









English (US) ·