2026 BitBox — newsletter phishing after shared email-provider (Brevo) breach
Data compromised
Newsletter subscriber phishing via legitimate-looking brand email path; BitBox warned all newsletter subscribers and reported phishing domains. Individual census not published.
Technical writeup
Verified BitBox warning — September 9, 2026 (X/Twitter @BitBoxSwiss). BitBox said phishing mail was sent to newsletter subscribers, warned all subscribers, contacted the provider, and reported phishing domains; noted multiple crypto companies share the same newsletter provider. Trade press (Recorded Future News / Malwarebytes) ties the wave to Brevo’s Sep 9–10 SAML SSO incident alongside Trezor and CoinTracking. BitBox customer census not published. Never enter recovery words from email. recordsAffected 0; companyConfirmed true.
Root cause
Phishing sent to BitBox newsletter subscribers after compromise of shared third-party newsletter/email provider (Brevo wave; BitBox noted other crypto brands share the same provider)
References
- https://x.com/BitBoxSwiss/status/2097793026336981079
- https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
- https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach
- https://status.brevo.com/incidents/pawbvhq8/write-up
- https://breachhistory.com/brevo/brevo-sso2026