Brevo (email marketing platform used by Trezor, BitBox, CoinTracking, Solana Mobile)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3kciyx…eJsLSummary
Brevo, a Paris-based email marketing and CRM platform (formerly Sendinblue) used by numerous crypto companies for newsletters, suffered a SAML single sign-on (SSO) authorization flaw that an attacker exploited around September 9-10, 2026 to access 138 customer accounts. Six of those accounts, including ones belonging to hardware wallet maker Trezor, hardware wallet maker BitBox, and portfolio tracker CoinTracking, were used to send convincing phishing emails to hundreds of thousands of real subscribers from the companies' legitimate domains, prompting some recipients to enter sensitive wallet information. Brevo says it closed the access path and issued a fix within hours, but the incident is a documented supply-chain risk for any crypto business or user relying on Brevo-delivered newsletters.
Connected Entities
1 entitiesTimeline(6 events)
9 September 2026
Trezor states, in its own official blog post, that Brevo suffered the security incident affecting 120 Brevo accounts (later revised by Brevo to 138).
Trezor official blogSeptember 2026
An attacker creates a Brevo account, enables SAML SSO on it, and invites legitimate Brevo customer accounts into that configuration, exploiting an authorization-scoping flaw to gain access to 138 customer accounts without needing their passwords.
SecurityWeek / Cointelegraph reporting on Brevo's postmortemSeptember 2026
Phishing emails are sent from 6 compromised Brevo accounts, including Trezor's, BitBox's, and CoinTracking's, to their real subscriber lists; Trezor's email (subject referencing an 'STM32 Entropy' vulnerability) reaches roughly 347,000 addresses. The malicious site is taken down at the DNS level roughly 20 minutes after detection, by which point about 2,500 recipients had clicked the link.
Trezor official blog / Cointelegraph10 September 2026
Brevo marks the incident "Resolved" on its public status page, stating the issue has been resolved and all affected services are functioning normally.
Brevo Status pageSeptember 2026
Brevo posts a public statement on X confirming an attacker accessed 120 (later revised to 138) customer accounts and used the access to send phishing emails; Brevo states the unauthorized access was closed as of 11:30 AM CEST.
Brevo official X accountSeptember 2026
Trezor, BitBox, and CoinTracking publicly warn customers of the phishing emails; mainstream outlets including TechCrunch, SecurityWeek, BleepingComputer, and Cointelegraph report on the breach and its impact on crypto users. Solana Mobile also issues a precautionary phishing warning to its users.
TechCrunchDecision Log
- hash: Ghr9cGpBafETecr4FoHEs96frKLUJwH5SJ7zh393f3C8
This investigation is cryptographically anchored to the Solana blockchain (1 event). 10 of 11 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 9/12/2026, 5:38:10 PM
last updated: 9/12/2026, 9:17:00 PM
avoid.net — verified advice for a post-truth world