← BitBox

2026 BitBox — newsletter phishing after shared email-provider (Brevo) breach

2026 Unknown records affected Share on X

Data compromised

Newsletter subscriber phishing via legitimate-looking brand email path; BitBox warned all newsletter subscribers and reported phishing domains. Individual census not published.

Technical writeup

Verified BitBox warning — September 9, 2026 (X/Twitter @BitBoxSwiss). BitBox said phishing mail was sent to newsletter subscribers, warned all subscribers, contacted the provider, and reported phishing domains; noted multiple crypto companies share the same newsletter provider. Trade press (Recorded Future News / Malwarebytes) ties the wave to Brevo’s Sep 9–10 SAML SSO incident alongside Trezor and CoinTracking. BitBox customer census not published. Never enter recovery words from email. recordsAffected 0; companyConfirmed true.

Root cause

Phishing sent to BitBox newsletter subscribers after compromise of shared third-party newsletter/email provider (Brevo wave; BitBox noted other crypto brands share the same provider)

References