
Email vendor Brevo suffered a security breach last week
that led to phishing attacks against the customers of several client companies. The issue has since been resolved, Brevo said.
There have been numerous episodes like this
throughout the business world, but this one was especially close to home for email marketers.
“On September 10th at 6:30 AM UTC we identified a security issue where an
attacker exploited a flaw in the way Brevo handles SAML SSO to gain access to 138 Brevo accounts. 6 of those accounts were used to send phishing emails to the contacts stored there, and for 43
accounts they exported the contacts,” the company posted last Thursday. “93 accounts have no meaningful activity.”
Brevo added, “The attacker no longer has access. At
8:30 AM UTC we closed the route the attacker used and signed out every user on the platform. There has been no further attacker activity since. We are contacting every affected customer directly with
details specific to their account.”
advertisement
advertisement
In addition, the firm says it is filing a legal complaint and employing a permanent fix.
Among the clients
affected was Trezor, a cryptocurrency company.
“Our third-party email provider has been breached,” Trezor posted. “Please be aware that the
email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attempt. Do not click on any link.”
The other clients
affected included CoinTracking and BitBox, The Record reports.
What caused the initial breach?
“The attacker created
a Brevo account and enabled single sign-on (SSO) on it, then invited legitimate Brevo users into that SSO configuration,” Brevo wrote. “Using their own identity provider, they were able to
sign in as those invited users, which by itself is expected behaviour for SSO.”
The post continued, “This access was not properly scoped: instead of being limited to the
single organization where SSO was enabled, it wrongly granted the attacker access to all organizations those users could reach.”
Brevo added, “The root cause is a boundary that was
not enforced: a login arriving through one company's SSO configuration should only ever reach that company's account.”
The company had not responded to a request for
further comment at deadline.