What is confirmed
Brevo says it identified the issue on 10 September at 06:30 UTC: SSO access granted in one organisation could improperly extend to other organisations available to invited users.
Its postmortem reports 138 accessible accounts: six used to send phishing, 43 with contacts exported and 93 without meaningful activity. Brevo says it closed the route and reset sessions at 08:30 UTC.
What it means
Messages travelled through legitimate sending infrastructure and could pass email authentication checks; a valid sender alone cannot establish safe content.
The Trezor case already covered here is one customer example; Brevo's account figures describe its own incident and should not be added to Trezor's contact counts.
What to do
Verify email alerts inside the official application without following links or installing software advertised in the message.
If your organisation uses Brevo, review vendor notices and sent campaigns, then inform recipients according to your confirmed scope.
Use the related SecurCheck tool, then confirm important decisions with an official source.



