Supply‑Chain Phishing Campaign Hits Crypto Newsletter Subscribers After Brevo Email‑Marketing Breach
What Happened – Attackers exploited a flaw in Brevo’s SAML SSO implementation, gaining access to 138 Brevo customer accounts. Six of those accounts were used to send phishing emails to the contact lists of cryptocurrency firms, and contacts were exported from 43 accounts.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of relying on third‑party communication platforms without continuous oversight.
- Highlights the need for documented vendor‑risk controls that can be monitored and presented as audit evidence.
- Shows why a defensible supply‑chain assurance program (continuous monitoring, evidence collection, incident response) is essential for maintaining trust.
Who Is Affected – Cryptocurrency companies (e.g., Trezor, CoinTracking, BitBox) and their newsletter subscribers; broader crypto‑focused user base.
Recommended Actions
- Review and tighten SAML SSO configurations for all third‑party services.
- Verify email authentication (DMARC, SPF, DKIM) for outbound newsletters.
- Incorporate the breached provider into your third‑party risk register and initiate continuous monitoring.
- Conduct targeted phishing awareness training for customers and staff.
- Preserve logs and evidence of the breach for audit readiness.
Source: Malwarebytes Labs
Technical Notes – The attacker leveraged a SAML SSO flaw (no public CVE disclosed) to hijack Brevo accounts, then crafted convincing phishing messages that mimicked legitimate crypto‑company communications. No malware payload was observed; the primary vector was credential harvesting via malicious links.