Brevo, the email marketing provider formerly known as Sendinblue, suffered a September 9-10, 2026 breach after an attacker exploited a vulnerability in its SAML SSO implementation. The attacker accessed 138 customer accounts, used six to send phishing emails and exported contact lists from another 43. Trezor said phishing emails reached about 347,000 newsletter subscribers, while BitBox and CoinTracking also confirmed their accounts were exploited. Solana Mobile warned users about elevated phishing risks; its account does not appear to have been among the compromised accounts. Brevo closed the attack vector at about 8:30 a.m. UTC on September 10 and reset active sessions. The incident exposed contact data rather than wallets or private keys, but created a larger pool of targets for impersonation and credential theft.