HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Supply‑Chain Phishing Campaign Hits Crypto Newsletter Subscribers After Brevo Email‑Marketing Breach

Attackers exploited a SAML SSO flaw in Brevo, accessed 138 accounts and used them to send phishing emails to cryptocurrency firms' newsletter subscribers. The incident underscores the need for continuous third‑party risk monitoring and audit‑ready evidence of vendor controls.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 malwarebytes.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
5 recommended
📰
Source
malwarebytes.com

Supply‑Chain Phishing Campaign Hits Crypto Newsletter Subscribers After Brevo Email‑Marketing Breach

What Happened – Attackers exploited a flaw in Brevo’s SAML SSO implementation, gaining access to 138 Brevo customer accounts. Six of those accounts were used to send phishing emails to the contact lists of cryptocurrency firms, and contacts were exported from 43 accounts.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of relying on third‑party communication platforms without continuous oversight.
  • Highlights the need for documented vendor‑risk controls that can be monitored and presented as audit evidence.
  • Shows why a defensible supply‑chain assurance program (continuous monitoring, evidence collection, incident response) is essential for maintaining trust.

Who Is Affected – Cryptocurrency companies (e.g., Trezor, CoinTracking, BitBox) and their newsletter subscribers; broader crypto‑focused user base.

Recommended Actions

  • Review and tighten SAML SSO configurations for all third‑party services.
  • Verify email authentication (DMARC, SPF, DKIM) for outbound newsletters.
  • Incorporate the breached provider into your third‑party risk register and initiate continuous monitoring.
  • Conduct targeted phishing awareness training for customers and staff.
  • Preserve logs and evidence of the breach for audit readiness.

Source: Malwarebytes Labs

Technical Notes – The attacker leveraged a SAML SSO flaw (no public CVE disclosed) to hijack Brevo accounts, then crafted convincing phishing messages that mimicked legitimate crypto‑company communications. No malware payload was observed; the primary vector was credential harvesting via malicious links.

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →