2026 CoinTracking — Brevo email-provider breach; phishing “refresh API keys” to newsletter list
Data compromised
Newsletter / contact-list abuse: phishing email titled “Data Breach Notice: Please refresh API Keys as soon as possible” with malicious link. Contact census not published; Brevo separately says contacts were exported from 43 of 138 accessed Brevo accounts across customers.
Technical writeup
Verified CoinTracking warning — September 9, 2026 (X/Twitter). CoinTracking stated its third-party email service provider Brevo experienced a security breach and that phishing mail titled “Data Breach Notice: Please refresh API Keys as soon as possible” was not legitimate. Part of the Sep 9–10 Brevo SAML SSO wave (138 Brevo accounts accessed; 6 used for phishing; 43 contact exports per Brevo postmortem). Same campaign hit Trezor (~347k) and BitBox newsletter subscribers. CoinTracking customer census not published. recordsAffected 0; companyConfirmed true.
Root cause
Third-party Brevo (email marketing) SAML SSO account compromise used to send phishing from CoinTracking’s legitimate sending path
References
- https://x.com/Coin_Tracking/status/2097800407103783325
- https://therecord.media/trezor-bitbox-cointracking-phishing-crypto-holders
- https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-by-scammers-after-email-marketing-provider-breach
- https://status.brevo.com/incidents/pawbvhq8/write-up
- https://breachhistory.com/brevo/brevo-sso2026