Cryptocurrency exchange Paymium recently alerted its users to a data breach involving its email service provider, Brevo. The incident, identified on September 10, 2026, highlights the risks associated with dependency on third-party services within the digital ecosystem. In total, 138 Brevo client accounts were compromised, with 43 of them having their contact lists exported by a malicious actor. The attacker exploited a critical vulnerability in the tool's Single Sign-On (SSO) system, bypassing security barriers that should have restricted cross-organizational access privileges.
The attack involved setting up a fraudulent SSO configuration, which allowed the intruder to hijack legitimate sessions and infiltrate third-party accounts. Although Brevo responded in under two hours to neutralize the flaw and reset active sessions, the intrusion resulted in unauthorized access to various pieces of personal information. The exposed data includes email addresses, full names, dates of birth, phone numbers, and countries of residence for the affected users. However, it is crucial to note that Paymium client funds, API keys, passwords, and digital wallets remained beyond the attacker's reach.
For the exchange, the main priority is now protecting its user base against phishing and social engineering attempts. The disclosure of precise contact details significantly increases the credibility of future fraud campaigns targeting investors. Paymium has urged its customers to exercise heightened vigilance, emphasizing that the company will never solicit seed phrases, access codes, or bank transfers via external communication channels.
This case once again underscores the fragility of software supply chains, where a vulnerability at a technical partner can compromise the data privacy of a third-party business. As Brevo actively collaborates with authorities to shed light on this unauthorized access, the incident serves as a reminder to the crypto industry of the imperative need to rigorously secure third-party integrations and strengthen access management protocols. Users are strongly advised to prioritize connecting directly via the official website rather than clicking on links received via email.