Phishing and scams

Brevo SSO incident: phishing sent through trusted email channels

Brevo says a SAML SSO scoping flaw exposed access to 138 customer accounts, six used to send phishing. What the supply-chain risk means.

Conceptual illustration: Brevo SSO incident: phishing sent through trusted email channels
Conceptual illustration · SecurCheck

What is confirmed

Brevo says it identified the issue on 10 September at 06:30 UTC: SSO access granted in one organisation could improperly extend to other organisations available to invited users.

Its postmortem reports 138 accessible accounts: six used to send phishing, 43 with contacts exported and 93 without meaningful activity. Brevo says it closed the route and reset sessions at 08:30 UTC.

What it means

Messages travelled through legitimate sending infrastructure and could pass email authentication checks; a valid sender alone cannot establish safe content.

The Trezor case already covered here is one customer example; Brevo's account figures describe its own incident and should not be added to Trezor's contact counts.

What to do

Verify email alerts inside the official application without following links or installing software advertised in the message.

If your organisation uses Brevo, review vendor notices and sent campaigns, then inform recipients according to your confirmed scope.

Check a suspicious sign

Use the related SecurCheck tool, then confirm important decisions with an official source.

Sources

  1. Brevo — compte rendu de l’incident SSO
  2. Trezor — conséquence pour ses abonnés