On 28 July 2026, customers were unable to sign in to Brevo or use several areas of the platform, encountering connection errors and failed page loads. The cause was an expired internal certificate within our infrastructure. The issue is fully resolved and all services are operating normally.
Duration: approximately 2 hours 50 minutes (12:28–15:18 UTC).
Affected: sign-in, including single sign-on; Account; Settings; Automation; CRM. Some requests to our public API also returned errors.
During the incident, affected customers could not log in, and pages in the affected areas failed to load or timed out. Sign-in began recovering at around 13:22 UTC, and full service was restored by 15:18 UTC.
No customer data was lost or altered.
An internal security certificate used by our infrastructure's coordination layer had expired. Connections of this type are only validated when they are established, so existing connections continued to work and the expiry went unnoticed. When those connections were re-established, the expired certificate was rejected, and the coordination layer for one part of our infrastructure lost consensus. Without it, the system could no longer reliably route incoming requests to the affected applications, so traffic from the internet was unable to reach them.
We renewed the expired certificates, provisioned replacement infrastructure nodes, removed the unhealthy ones, and confirmed full recovery before closing the incident.
Automated expiry monitoring for all internal certificates, across every production cluster. The absence of this monitoring is what allowed an expired certificate to go unnoticed. We audited every cluster immediately afterwards and renewed any certificate at or approaching expiry.
More reliable renewal tooling, so that a renewal is always applied in full and can be verified rather than assumed.
Better diagnostics for this layer of our infrastructure — additional monitoring and log retention — so that a similar failure is identified faster.
Additional capacity headroom on the affected infrastructure.
We are sorry for the disruption this caused. We know how much you rely on Brevo being available, and we are addressing both the specific cause and the gap in monitoring that allowed it to go undetected.