A French email marketing company called Brevo, which previously operated under the name Sendinblue, has experienced two major security incidents that have raised concerns about its role in potential supply chain attacks. Based in Paris and serving over 600,000 clients, Brevo reported the first incident on September 10, when an attacker exploited a vulnerability in the SAML authentication system. This system is commonly used for single sign-on (SSO) across multiple platforms. The attacker created a Brevo account and then invited other users to join their SSO configuration, thereby gaining access to 138 Brevo accounts. Six of these accounts were used to launch phishing campaigns, one of which targeted the cryptocurrency provider Trezor. Additionally, data from 43 other accounts was stolen.
A second incident occurred just four days later, when an attacker used a compromised Cloudflare API key to inject a malicious script onto Brevo’s website and related domains, including "Brevo.com" and "Sibforms.com." The script appeared to ask users to verify their humanity by copying and pasting text, a method known as ClickFix. This technique tricks users into unknowingly executing a command on their own devices. The script also attempted to install a plugin on websites of users who were logged in as administrators of WordPress. According to the Dutch cybersecurity firm Sansec, this attack affected more than 125,000 web pages.
Brevo stated that the data breach affected only a limited number of accounts. However, the compromised data included sensitive user information such as email addresses, phone numbers, and personal identification details like first and last names. The French cryptocurrency exchange platform Paymium confirmed that its users’ data had been accessed through a Brevo account. Paymium assured users that data related to their wallets or tax status was not affected, but it warned that the leaked information, while limited, could still be used to identify cryptocurrency owners.
The incidents have highlighted the risks associated with third-party service providers in the digital ecosystem. Even though Brevo emphasized that the breach was limited in scope, the potential for such attacks to affect multiple organizations through a single compromised service remains a growing concern for cybersecurity experts and businesses alike.
French Email Marketing Firm Brevo Faces Major Security Incidents and Data Leaks
AI-rewritten from original reportingHow it works
brevosecurity-breachphishingsupply-chaincloudflaresaml



