Write-up
Attacker gained access to client accounts

What happened

On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts. 6 of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts they exported the contacts. 93 accounts have no meaningful activity.

The attacker no longer has access. At 8:30 AM UTC we closed the route the attacker used and signed out every user on the platform. There has been no further attacker activity since. We are contacting every affected customer directly with details specific to their account.


How the attacker got in

The attacker created a Brevo account and enabled single sign-on (SSO) on it, then invited legitimate Brevo users into that SSO configuration. Using their own identity provider, they were able to sign in as those invited users, which by itself is expected behaviour for SSO. 

This access was not properly scoped: instead of being limited to the single organization where SSO was enabled, it wrongly granted the attacker access to all organizations those users could reach. 

What we have changed 

The root cause is a boundary that was not enforced: a login arriving through one company's SSO configuration should only ever reach that company's account. 

We have since closed the entry point as of 8:30am UTC 10.09.2026 today, and reset all active sessions.

We are deploying a permanent fix that strictly limits SSO access to only the organization that owns the SSO configuration, and re-enable SSO invitations. 

If you have received some of these emails

These messages were sent through legitimate infrastructure, so they passed the usual email authentication checks and looked genuine. 

We’ve disabled all links of those emails, but as a preventive measure, please do not click them.

Customers trust us with access to their audiences, and in this case we failed to protect it.

We are filing a legal complaint and acknowledge and apologize for where we exposed our clients. Brevo is committed to fully cooperating fully with the authorities.

Powered by