Email marketing platforms are the quiet infrastructure of the internet, the unglamorous pipes that move newsletters and alerts from companies to inboxes. A breach at Brevo, the email marketing service formerly known as Sendinblue, exposed a vulnerability that sent ripples across the crypto industry, prompting Solana Mobile to warn its users about elevated phishing risks.
The breach unfolded on September 9-10, 2026, when an attacker exploited a flaw in Brevo’s SAML SSO handling, a single-sign-on authentication mechanism that, when misconfigured or vulnerable, can hand an outsider the keys to a remarkably wide door.
What actually happened
The attacker gained unauthorized access to 138 Brevo customer accounts using the SSO vulnerability. Of those, six accounts were weaponized to send phishing emails directly to subscribers. Another 43 accounts had their contact lists exported, meaning email addresses quietly left the building even if no phishing message followed immediately.
Brevo identified the intrusion and closed the attack vector by approximately 8:30 AM UTC on September 10, resetting active sessions to cut off further unauthorized access.










