On September 9, 2026, an attacker infiltrated the email‑marketing platform Brevo (formerly Sendinblue) and compromised the accounts of 138 customers. By harvesting contact lists from 43 of those accounts, the intruder was able to send phishing emails to the newsletter subscribers of several cryptocurrency firms.

Brevo’s post‑mortem, released the following day, explains that the breach began with stolen login credentials belonging to legitimate users. A flaw in the platform’s authentication system amplified the intrusion, allowing the attacker to access 120 accounts. Six of those compromised accounts were used to dispatch fraudulent messages, while the attacker exported contacts from 43 accounts before being removed from Brevo’s systems. The company has since applied a permanent fix and pledged full cooperation with law‑enforcement agencies.

Three crypto companies—Trezor, CoinTracking and BitBox—were the victims of the phishing attack. Each sent urgent‑looking security alerts that appeared to originate from their own domains. Trezor’s email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” urged users to click a link that purportedly fixed a hardware flaw. The company confirmed on social media that the message was not sent by Trezor and that the breach involved a third‑party email provider. Trezor also noted that it had recently suffered a separate data breach exposing the personal details of 81,000 customers.

CoinTracking’s phishing email bore the headline “Data Breach Notice: Please refresh API Keys as soon as possible” and contained a malicious link. BitBox warned all newsletter subscribers that it had identified the phishing domains and reported them to the provider; it added that most of the fraudulent links had already been taken down.

The success of the attacks hinged on the attacker’s access to the contact lists of the crypto firms. By using the legitimate company domains and mimicking urgent security notices, the phishing emails looked authentic to many recipients. Several users reported that the messages were convincing enough to click the links, which redirected them to counterfeit websites that closely resembled the real platforms.

Brevo’s analysis confirms that 138 accounts were breached, six of which were used to send phishing emails. The attacker exported contacts from 43 accounts before being removed from the system.

This incident follows a string of data breaches that have raised alarm about the exposure of identifying information for cryptocurrency owners. Over the past year, the U.S. Department of Justice has cited stolen lists of crypto owners in investigations of theft rings. A 2025 DOJ report highlighted that criminals used data from crypto companies to rank targets.

In addition to the Brevo breach, the crypto industry has seen a rise in “wrench attacks,” where wealthy owners are targeted in real‑world assaults. According to blockchain security firm CertiK, wrench‑attack losses grew 33 % year‑over‑year, reaching $124 million in 2026 compared with $10.5 million in the first half of 2025.

The Brevo breach underscores the importance of securing third‑party services that handle customer data. Crypto companies that rely on external email providers must verify that those providers have robust security controls and incident‑response capabilities.

At present, there is no direct evidence that any cryptocurrency funds were compromised in the phishing campaign. The affected companies have not reported losses and are continuing to investigate the extent of the breach.

Brevo has issued a warning that the attacker’s access has been closed and that the compromised accounts have been secured. The company has also released a detailed technical explanation of how the breach occurred and plans to cooperate with law‑enforcement agencies.

Crypto users are advised to remain vigilant, verify the authenticity of urgent security messages, and avoid clicking on links from unfamiliar or suspicious emails. The incident serves as a reminder that even well‑known crypto firms can be vulnerable when third‑party services are compromised.