Commentary

Brevo Breach: Email Firm Plugs Up A Short-Lived Security Issue

Email vendor Brevo suffered a security breach last week that led to phishing attacks against the customers of several client companies. The issue has since been resolved, Brevo said.  

There have been numerous episodes like this throughout the business world, but this one was especially close to home for email marketers. 

“On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts. 6 of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts they exported the contacts,” the company posted last Thursday. “93 accounts have no meaningful activity.”

Brevo added, “The attacker no longer has access. At 8:30 AM UTC we closed the route the attacker used and signed out every user on the platform. There has been no further attacker activity since. We are contacting every affected customer directly with details specific to their account.”

advertisement

advertisement

In addition, the firm says it is filing a legal complaint and employing a permanent fix.  
Among the clients affected was Trezor, a cryptocurrency company.  

“Our third-party email provider has been breached,” Trezor posted. “Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”

The other clients affected included CoinTracking and BitBox, The Record reports. 

What caused the initial breach?

“The attacker created a Brevo account and enabled single sign-on (SSO) on it, then invited legitimate Brevo users into that SSO configuration,” Brevo wrote. “Using their own identity provider, they were able to sign in as those invited users, which by itself is expected behaviour for SSO.” 

The post continued, “This access was not properly scoped: instead of being limited to the single organization where SSO was enabled, it wrongly granted the attacker access to all organizations those users could reach.”

Brevo added, “The root cause is a boundary that was not enforced: a login arriving through one company's SSO configuration should only ever reach that company's account.” 

The company had not responded to a request for further comment at deadline. 

Next story loading loading..