Verify a decision
Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.
How verification works
- We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (
payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction. - We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
- You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is
AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.
Decision
publish · Brevo
- Sequence
- #1
- Score
- →
- Cluster
- mainnet-beta
- Slot
- 446487759
- Off-chain at
- 2026-09-12T17:35:51.297Z
- Anchored at
- —
- Block time
- —
Independent verification
- 1. Database (off-chain)
- 3XXKRs4EKuUw5gN1eS5voWE85XgG45Se7hqUropXwNF3
- 2. Recomputed (your browser)
- computing…
- 3. On-chain (Solana memo)
- fetching…
Canonical bytes hashed (16853 chars)
{"actor":"system:backfill","investigation_id":"0a8fb862-3893-43c1-b81c-9a131e64ab3c","kind":"publish","page_slug":"brevo","published_at":"2026-09-12T17:35:51.174Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Brevo","sections":[{"content":"Brevo was founded in 2012 in Paris, France, under the name Sendinblue by Armand Thiberge. The company rebranded to Brevo in 2023 to reflect its expansion beyond email marketing into CRM, SMS, and customer data platform (CDP) services. As of 2026, Brevo serves more than 600,000 customers across over 180 countries and processes billions of emails per month. Following a reported funding round of approximately €500 million in late 2025, the company reached unicorn status while remaining privately held. Brevo is headquartered in Paris with offices in North America, Europe, and India, and positions itself as a GDPR-first alternative to US-centric platforms such as Mailchimp and HubSpot.","heading":"Company Background","severity":"low","sources":[{"credibility":2,"name":"Brevo company overview — Omnisend review","type":"other","url":"https://www.omnisend.com/blog/brevo-review/"}]},{"content":"On September 10, 2026, Brevo's security team identified unauthorized access to customer accounts beginning at approximately 06:30 UTC. According to Brevo's official post-mortem, the attacker created a legitimate Brevo account, enabled single sign-on (SSO) on it, and then invited genuine Brevo customers into that SSO configuration. Using their own identity provider, the attacker authenticated as those invited users — behavior that is expected in SSO flows. However, a critical authorization boundary flaw in Brevo's SAML SSO implementation failed to scope the attacker's session to a single organization. Instead, access was wrongly granted to all organizations those invited users could reach across the entire platform. Brevo closed the exploitation pathway and force-logged all active sessions by approximately 08:30 UTC the same day, approximately two hours after detection. No passwords or wallet credentials were stored in Brevo's systems; the data exposed consisted of email addresses and, in at least one case, language preferences. Brevo stated in its post-mortem: 'Customers trust us with access to their audiences, and in this case we failed to protect it.' The company also stated it filed a legal complaint with authorities.","heading":"September 2026 SAML SSO Breach","severity":"critical","sources":[{"credibility":1,"name":"Brevo official incident post-mortem (September 10, 2026)","type":"official","url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE/write-up"},{"credibility":1,"name":"SecurityWeek: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"credibility":2,"name":"CoinTelegraph: Brevo Login Flaw Exposes Trezor, BitBox, CoinTracking to Phishing","type":"news_article","url":"https://cointelegraph.com/news/brevo-login-flaw-trezor-bitbox-cointracking-phishing"},{"credibility":2,"name":"Brevo on X — post-mortem announcement","type":"social_media","url":"https://x.com/brevo_official/status/2098113985685971432"}]},{"content":"Brevo's post-mortem confirmed that 138 customer accounts were accessed through the SAML SSO flaw. Of those, 6 accounts were used to send phishing emails to contacts stored in those accounts, and 43 accounts had their contact lists exported by the attacker. The remaining 93 accounts showed no meaningful activity beyond the unauthorized login. Brevo serves hundreds of thousands of customers; the 138 compromised accounts represent a narrow but strategically selected subset, as multiple affected accounts belonged to cryptocurrency-sector companies with large subscriber lists.","heading":"Scope of Compromised Accounts","severity":"high","sources":[{"credibility":1,"name":"Brevo official incident post-mortem (September 10, 2026)","type":"official","url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE/write-up"},{"credibility":1,"name":"SecurityWeek: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"}]},{"content":"Several cryptocurrency companies confirmed their Brevo accounts were among those compromised. Trezor, a manufacturer of hardware cryptocurrency wallets, disclosed that approximately 347,000 newsletter subscribers received a phishing email with the subject line 'Critical Security Alert: STM32 Entropy Vulnerability.' The email falsely claimed a hardware flaw in STM32 microcontrollers used in Trezor devices could expose seed phrases to brute-force attacks, and directed recipients to download a malicious application requesting wallet backup credentials. Trezor stated it treated all roughly 347,000 newsletter addresses as known to the attacker until further information from Brevo became available. BitBox, a Swiss hardware wallet manufacturer, confirmed its full newsletter and tutorial subscriber list was reached. CoinTracking, a cryptocurrency tax and portfolio tracking service, confirmed its Brevo account was compromised and that a phishing email with the subject line 'Data Breach Notice: Please refresh API Keys as soon as possible' was sent to its contacts. Solana Mobile issued a public warning to its users about elevated phishing risks following the incident; according to Crypto Briefing, Solana Mobile's own Brevo account was not confirmed as directly used to send phishing emails, but the company issued precautionary guidance given the broader exposure across the industry. Because the phishing emails were delivered via Brevo's own infrastructure using the legitimate sender accounts of these companies, they passed standard email authentication checks (SPF, DKIM, DMARC), making them significantly more convincing to recipients.","heading":"Crypto Companies Affected and Phishing Campaigns","severity":"critical","sources":[{"credibility":1,"name":"Trezor official blog: Security incident at Brevo, our third-party email provider","type":"official","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"credibility":1,"name":"SecurityWeek: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"credibility":2,"name":"CoinTelegraph: Brevo Login Flaw Exposes Trezor, BitBox, CoinTracking to Phishing","type":"news_article","url":"https://cointelegraph.com/news/brevo-login-flaw-trezor-bitbox-cointracking-phishing"},{"credibility":2,"name":"Crypto Briefing: Solana Mobile warns users of phishing risks after Brevo breach","type":"news_article","url":"https://cryptobriefing.com/solana-mobile-phishing-warning-brevo-breach/"}]},{"content":"Trezor reported that approximately 2,500 recipients clicked the malicious link contained in the phishing emails before the phishing site was taken down. Trezor disabled the domain at the DNS level within approximately 20 minutes of detecting the campaign. According to Trezor's official statement, clicking the link alone did not result in exposure; risk of loss was limited to users who proceeded to enter wallet backup credentials into the malicious application. Trezor publicly advised any user who had entered their wallet backup online to immediately move their funds to a new wallet. The total number of users who suffered asset losses as a result of this incident has not been publicly disclosed by any party as of the date of this report. The data held by Brevo consisted only of email addresses; Brevo confirmed that no passwords, wallet data, or other personal information beyond email addresses were stored in its systems.","heading":"User Impact and Malicious Link Engagement","severity":"high","sources":[{"credibility":1,"name":"Trezor official blog: Security incident at Brevo, our third-party email provider","type":"official","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"credibility":1,"name":"SecurityWeek: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"credibility":1,"name":"BleepingComputer: Trezor 347,000 users targeted in phishing attacks after Brevo breach","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/"}]},{"content":"This incident illustrates a supply-chain attack pattern in which a shared marketing infrastructure provider becomes an attack surface for downstream customers. Because email marketing platforms hold contact lists on behalf of multiple organizations and are authorized to send emails from those organizations' domains, a platform-level authentication flaw can be weaponized to simultaneously target the subscribers of many organizations. In this case, the attacker appears to have specifically targeted cryptocurrency-sector Brevo accounts, suggesting deliberate selection of high-value targets for wallet credential harvesting. The incident is categorically distinct from a direct compromise of Trezor, BitBox, CoinTracking, or Solana Mobile systems; those companies' own infrastructure was not breached. However, their subscribers were exposed through their reliance on a shared third-party service.","heading":"Supply-Chain Risk Vector","severity":"high","sources":[{"credibility":2,"name":"Malwarebytes: Crypto customers targeted by scammers after email marketing provider breach","type":"news_article","url":"https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach"},{"credibility":2,"name":"CoinTelegraph: Brevo Login Flaw Exposes Trezor, BitBox, CoinTracking to Phishing","type":"news_article","url":"https://cointelegraph.com/news/brevo-login-flaw-trezor-bitbox-cointracking-phishing"}]},{"content":"Brevo identified the intrusion at approximately 06:30 UTC on September 10, 2026, and closed the attack vector by approximately 08:30 UTC, a window of approximately two hours. The company force-logged all active sessions across the platform as part of containment. A permanent fix restricting SSO access strictly to the owning organization was deployed, and the SSO invitation functionality was subsequently re-enabled. Brevo published a full post-mortem on September 10, 2026, stating: 'Customers trust us with access to their audiences, and in this case we failed to protect it.' The company confirmed it filed a legal complaint with authorities and stated it was contacting all affected customers directly. As of the time of reporting, no regulatory action or fine has been publicly announced in connection with this incident.","heading":"Brevo's Response and Remediation","severity":"medium","sources":[{"credibility":1,"name":"Brevo official incident post-mortem (September 10, 2026)","type":"official","url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE/write-up"},{"credibility":2,"name":"Brevo on X — post-mortem announcement","type":"social_media","url":"https://x.com/brevo_official/status/2098113985685971432"},{"credibility":1,"name":"SecurityWeek: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"}]}],"sources_used":[{"credibility":1,"name":"Brevo official incident post-mortem (September 10, 2026)","type":"official","url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE/write-up"},{"credibility":1,"name":"Trezor official blog: Security incident at Brevo, our third-party email provider","type":"official","url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"credibility":1,"name":"SecurityWeek: Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack","type":"news_article","url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"credibility":1,"name":"BleepingComputer: Trezor 347,000 users targeted in phishing attacks after Brevo breach","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/"},{"credibility":2,"name":"CoinTelegraph: Brevo Login Flaw Exposes Trezor, BitBox, CoinTracking to Phishing","type":"news_article","url":"https://cointelegraph.com/news/brevo-login-flaw-trezor-bitbox-cointracking-phishing"},{"credibility":2,"name":"Crypto Briefing: Solana Mobile warns users of phishing risks after Brevo breach","type":"news_article","url":"https://cryptobriefing.com/solana-mobile-phishing-warning-brevo-breach/"},{"credibility":2,"name":"Malwarebytes: Crypto customers targeted by scammers after email marketing provider breach","type":"news_article","url":"https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach"},{"credibility":2,"name":"Brevo on X — post-mortem announcement","type":"social_media","url":"https://x.com/brevo_official/status/2098113985685971432"}],"summary":"Brevo (formerly Sendinblue) is a Paris-based email marketing and CRM platform serving over 600,000 customers globally. On September 10, 2026, an attacker exploited a critical authorization boundary flaw in Brevo's SAML SSO implementation to compromise 138 customer accounts, six of which were used to send phishing emails to hundreds of thousands of cryptocurrency users. The incident is a confirmed supply-chain risk event, with Brevo having issued a public post-mortem acknowledging the flaw and deploying a fix.","timeline":[{"date":"2012-01-01","event":"Brevo founded in Paris, France as Sendinblue by Armand Thiberge.","source":"Omnisend Brevo review","source_url":"https://www.omnisend.com/blog/brevo-review/"},{"date":"2023-01-01","event":"Sendinblue rebrands to Brevo, reflecting expansion into CRM, SMS, and CDP services.","source":"Omnisend Brevo review","source_url":"https://www.omnisend.com/blog/brevo-review/"},{"date":"2026-09-10","event":"At approximately 06:30 UTC, Brevo's security team detects unauthorized access to customer accounts via a SAML SSO authorization boundary flaw. Attacker had created a rogue SSO configuration and invited legitimate Brevo customers into it, gaining cross-organization access without their passwords.","source":"Brevo official incident post-mortem","source_url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE/write-up"},{"date":"2026-09-10","event":"Phishing emails begin reaching subscribers of affected Brevo customers, including approximately 347,000 Trezor newsletter subscribers. Subject lines include 'Critical Security Alert: STM32 Entropy Vulnerability' (Trezor) and 'Data Breach Notice: Please refresh API Keys as soon as possible' (CoinTracking).","source":"SecurityWeek","source_url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"},{"date":"2026-09-10","event":"Trezor detects the phishing campaign and disables the malicious domain at the DNS level within approximately 20 minutes of detection. Approximately 2,500 recipients had already clicked the malicious link before takedown.","source":"Trezor official blog","source_url":"https://trezor.io/blog/news/security-incident-at-brevo-our-third-party-email-provider"},{"date":"2026-09-10","event":"Brevo closes the SAML SSO attack vector and force-logs all active sessions by approximately 08:30 UTC (11:30 AM CEST), approximately two hours after initial detection.","source":"Brevo official incident post-mortem","source_url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE/write-up"},{"date":"2026-09-10","event":"Brevo publishes a full post-mortem confirming 138 accounts were compromised (6 used for phishing campaigns, 43 had contacts exported, 93 with no meaningful activity), acknowledges the flaw, and states a legal complaint was filed.","source":"Brevo official incident post-mortem","source_url":"https://status.brevo.com/incidents/01M266V1CZKJQNGZRNEGFD5CQE/write-up"},{"date":"2026-09-11","event":"Trezor, BitBox, CoinTracking, and Solana Mobile publicly warn their users of the phishing incident. SecurityWeek, CoinTelegraph, Crypto Briefing, BleepingComputer, and Malwarebytes report on the breach.","source":"SecurityWeek","source_url":"https://www.securityweek.com/trezor-says-347000-users-received-phishing-emails-after-brevo-hack/"}]},"v":1}