2026 Brevo — SAML SSO flaw; attacker accessed 138 client accounts (6 used for phishing)
Data compromised
138 Brevo customer accounts accessed; contacts exported from 43 accounts; phishing emails sent from 6 accounts (including Trezor). Aggregate contact census across all customers not published.
Technical writeup
Verified Brevo status write-up — September 10, 2026 (UTC). Attacker exploited a SAML SSO handling flaw: after creating an account, enabling SSO, and inviting legitimate users, the IdP login was not scoped to that org and wrongly reached other organizations those users could access. Brevo identified the issue at 6:30 AM UTC, closed the route and signed out all users by 8:30 AM. Impact: 138 accounts accessed; contacts exported from 43; phishing from 6. Legal complaint filed. Customer contact totals not published — recordsAffected 0; companyConfirmed true. See also trezor-email-provider2026 for the Trezor victim impact (~347k).
Root cause
SAML SSO boundary flaw: attacker-created SSO org invitations wrongly granted access across invited users’ organizations