Digital marketing platform Brevo was recently hit by a major cyberattack, exposing a critical vulnerability within its systems. By exploiting a flaw related to the SAML SSO protocol, malicious actors managed to breach 138 client accounts on September 10. While the company quickly neutralized the entry point used, the operational consequences are already proving significant for the digital ecosystem.

The aftermath of this intrusion highlights a targeted exploitation of data: while no suspicious activity was detected on some accounts, 43 of them had their contact databases exported, and 6 accounts were used as vectors for sending massive amounts of fraudulent emails. This maneuver occurs in a global context where the sophistication of attacks, boosted by artificial intelligence, allows hackers to increase their execution speed and the credibility of their phishing campaigns.

The cryptocurrency sector finds itself on the front lines of this wave of phishing. Specialized entities such as CoinTracking, Trezor, and BitBox have been identified as the primary targets of these deceptive messages. Disguised as urgent security alerts, often prompting users to reset their API keys, these emails aim to steal sensitive access to digital wallets. Investors must remain vigilant against these increasingly convincing digital identity thefts.

Beyond the technical response provided by Brevo, which has pledged to contact each impacted user individually, this incident underscores the vulnerability of third-party services used by Web3 companies for their communications. Security issues surrounding customer data are becoming critical, as the theft of a contact list is enough to compromise the financial security of a large number of individuals. It is imperative for users to systematically verify the authenticity of senders and never disclose private keys or passwords, regardless of how alarmist a received message may appear.