6 min read By Excello Mail Team

One Login Flaw at an Email Marketing Platform Reached 138 Companies. The Phishing It Sent Passed DMARC Because It Was Genuinely Them.

An authorization flaw in Brevo's SSO setup let one attacker reach 138 client accounts on the email marketing platform, sending phishing to 347,000 Trezor newsletter subscribers and forging fake breach notices through BitBox and CoinTracking. Every message cleared SPF, DKIM, and DMARC, because it went out through the brands' own authorized sending infrastructure.

On September 9, 2026, roughly 347,000 people who had signed up for Trezor’s newsletter received an email warning them that a factory defect in the STM32 microcontroller used in their hardware wallet made their recovery seed vulnerable to brute-force attacks. The claim was false. The email, though, was completely real: it came from Trezor’s own authorized mailing infrastructure, carried a valid DKIM signature, and passed DMARC without a single check flagged. The attacker did not spoof Trezor. They reached Trezor’s account on Brevo, the email marketing platform Trezor uses to run that newsletter, and sent the message from the inside.

A Boundary That Was Supposed to Stop at One Company

Brevo’s postmortem, published the day after the campaign went out, traced the access back to a flaw in how the platform handles SAML single sign-on. The attacker created their own Brevo account, enabled SSO on it, and invited legitimate Brevo users, people who already belonged to other companies’ accounts, into that configuration. Access was supposed to stay confined to the attacker’s own organization. Instead, an authorization boundary failed, and the invitation extended the attacker’s reach into every account those invited users could touch elsewhere on the platform.

That single flaw ultimately reached 138 client accounts. Brevo says six of them were used to actually send phishing emails to the contacts stored there, forty-three had their contact lists exported without a message going out, yet, and the remaining accounts showed no further activity the platform could detect. Trezor, the Swiss hardware wallet maker BitBox, and the crypto portfolio tracker CoinTracking all confirmed they were among the six.

Three Brands, Three Lures, One Shared Mail Path

Each affected company’s list got a different pretext, built to fit the brand sending it. Trezor subscribers got the fake STM32 vulnerability warning, with a link to a page requesting a wallet backup phrase to check exposure. CoinTracking’s list received a message titled “Data Breach Notice: Please refresh API keys as soon as possible,” using the appearance of a security notice to push a credential-harvesting link. BitBox’s subscribers were hit with a similarly framed message. In every case, the email itself carried nothing false about its origin. It really did come from the company’s newsletter infrastructure, through the same Brevo sending domain that legitimate campaigns use every week.

Trezor pulled the phishing domain at the DNS level about twenty minutes after the campaign went out. In that window, roughly 2,500 people clicked the link. None of the three companies reported evidence of stolen recovery phrases, drained wallets, or compromised product credentials; the data actually exposed in the Brevo accounts was limited to subscriber email addresses and language preferences.

Why DMARC Had Nothing to Object To

DMARC, SPF, and DKIM answer exactly one question: was this message authorized by the domain it claims to represent? For the mail Brevo sent on Trezor’s, BitBox’s, and CoinTracking’s behalf, the honest answer was yes. These companies had already done the alignment work, configured Brevo as an approved sender, and published the SPF and DKIM records that make that sending path legitimate. None of that changed when an attacker walked in through Brevo’s own access controls. The compromise happened a layer above anything DMARC evaluates, inside the marketing platform’s authorization logic, in an account boundary that was never supposed to be crossable from outside the company that owned it.

This is the same shape of problem this blog keeps returning to, just one step further upstream. A hijacked mailbox, a compromised vendor account, or a misconfigured SaaS sender all produce identical, honestly authenticated mail, because DMARC was never built to ask who has access to the systems that are allowed to send as you. It was built to ask whether the domain approved the send, and every one of those systems can answer yes truthfully while being controlled by someone who should not be there.

What This Means for Your Program

Every marketing and transactional platform in your SPF record is a standing extension of trust. If your DMARC setup authorizes Brevo, Mailchimp, SendGrid, or any other ESP to send as your domain, an access-control failure on their side becomes a DMARC-passing phishing campaign on yours, with zero warning from your own authentication reports.

Ask your ESP how it scopes invited users and SSO configurations, not just how it scopes API keys. The Brevo flaw lived in an authorization boundary around collaborative account access, a part of vendor security most customers never think to ask about because it feels like an internal platform detail rather than a risk to their own domain.

A breach notice arriving by email is now a lure pattern in its own right. CoinTracking’s list was told to “refresh your API keys” in a message imitating exactly the kind of notice a real breach response sends. Any process for communicating an actual incident needs a channel outside email that customers already know to trust, so a copycat notice cannot ride in on the real one’s credibility.

Subscriber lists are worth stealing even when they hold nothing but an email address. Neither Brevo nor the three affected companies lost passwords or financial data in this incident, yet the exposure was still enough to launch a targeted, brand-accurate phishing run against hundreds of thousands of people. Treat marketing contact data with the same access discipline as anything else that can be weaponized against your users.

The Takeaway

Trezor, BitBox, and CoinTracking did the authentication work correctly. Their SPF and DKIM records were right, their DMARC alignment held, and every phishing email their subscribers received passed cleanly, because it was genuinely sent through infrastructure those companies had legitimately authorized. The failure was one layer removed, in an access boundary at the platform doing the sending. Every vendor with standing permission to send as your domain deserves the same scrutiny you would give a compromised mailbox, because to DMARC, that is exactly what they are.


DMARC tells you whether a message was authorized to send as your domain. It cannot tell you whether the platform you authorized has locked down who else can reach your account inside it. Excello Mail gives you continuous, plain-language visibility into every source sending on your domain’s behalf, so a marketing platform quietly compromised at the account level shows up as a change worth investigating, not a clean report you skim past. Sign up for free to Excello Mail and see exactly who is sending as you, including the vendors you already trust.