We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Brevo: The Data Breach Explained, and What an SME Should Check Immediately Afterward

Brevo, the French email marketing platform used by tens of thousands of small and medium-sized businesses, suffered two security incidents in early September 2026: a breach via an authentication vulnerability, followed by the theft of a technical key that allowed malicious code to be injected into client websites. This week, Trezor and Paymium confirmed the extent of the impact on their users. Here’s what an SME that uses Brevo—or one of its widgets—needs to check.

Brevo: The Data Breach Explained, and What an SME Should Check Immediately Afterward

In summary. Brevo, la plateforme française d'emailing utilisée par des dizaines de milliers de PME, a subi deux incidents de sécurité début septembre 2026 : une intrusion par faille d'authentification, puis le vol d'une clé technique ayant permis d'injecter du code malveillant sur des sites clients. Cette semaine, deux entreprises touchées ont détaillé l'ampleur des dégâts pour leurs utilisateurs.

What Happened

Brevo (formerly Sendinblue) is one of the most widely used email and marketing tools among French small and medium-sized businesses for sending newsletters and transactional emails, as well as for contact forms and chat widgets integrated into websites.

On September 10, 2026, a vulnerability in Brevo's single sign-on (SSO) system allowed an attacker to compromise 138 customer accounts. Six of these accounts were used to send fake security emails to users, and the contacts from 43 accounts were exported.

On September 14, a second incident occurred: a technical key granting access to Brevo’s delivery infrastructure was stolen. For about five and a half hours, the attackers used it to dynamically modify the code delivered by Brevo forms and widgets installed on client websites, displaying a fake verification message that prompted visitors to copy and paste a command onto their computers. On WordPress, a fake plugin called “Web Media Optimizer” was also used as a backdoor. The security firm Sansec estimates that more than 100,000 sites using Brevo components may have distributed this code during the attack window.

Brevo claims to have revoked the compromised key, removed the malicious code, and cleared its caches. But the fallout continues to unfold: this week, the crypto wallet manufacturer Trezor confirmed that 347,000 of its users had received a fake security alert email sent from a hacked Brevo account, and the French crypto platform Paymium announced on September 22 that its customers’ personal information (names, dates of birth, phone numbers, and countries of residence) had been leaked through this breach.

Does this apply to me?

The risk depends on how your company uses Brevo, but it can also come from outside sources.

If your small or medium-sized business uses Brevo for its email campaigns, transactional emails, or customer support, your login credentials and contacts may have been among the accounts affected on September 10, or may simply have been exposed due to the service’s overall vulnerability.

If your website includes a contact form, a chat widget, or a Brevo script, it may have distributed the malicious code from September 14 without your knowledge, exposing your own visitors to this attack.

Even if you don't use Brevo, your employees or customers may receive phishing emails that exploit this news by mimicking a credible security alert, similar to the one that affected Trezor users.

What to Do Now

Three checks to perform in the coming days, in order of priority:

1. Check your Brevo usage. If your company has a Brevo account, change the password, regenerate the API keys, and enable two-factor authentication if you haven't already. Also check the history of recent logins.

2. Check your website. If you have a form, chat, or Brevo SDK installed on your site, have your service provider verify that no unknown plugins or scripts appeared around September 14–15, especially on WordPress. If in doubt, a full scan is recommended.

3. Remind your teams of the proper precautions. No legitimate email asks you to copy and paste a command into a terminal or command window: this is exactly the method used here (a technique known as “ClickFix”). A brief reminder to your teams can prevent many infections. Our guide on phishing details the precautions to take when faced with this type of message.

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

In a nutshell

Brevo experienced two incidents in early September: compromised customer accounts, followed by the theft of a technical key that allowed malicious code to be injected into tens of thousands of websites. The full extent of the impact on its customers is still becoming clear this week. If your company uses Brevo or one of its widgets, a few targeted checks are all it takes to mitigate the risk.

Frequently asked questions

I don't use Brevo—should I be concerned? The immediate risk is low. Just be on the lookout for emails that appear to be security alerts from a service you use; that's the method being exploited in this incident.

How can I tell if my Brevo account is one of the 138 affected accounts? Brevo has notified the affected accounts directly. If you're unsure, change your login credentials and check the login history from your admin interface.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
Illustration of an agent-based infrastructure operator
Cybersecurity

Agent-Based Infrastructure Operator: Definition and Role

An agent-based infrastructure operator designs, secures, and continuously operates the layer that enables AI agents to act within the information system. Definition, components, a Microsoft 365 example, and eight questions to help you choose an operator.
September 24, 2026
Illustration: iA Agent
Cybersecurity

Agent-Based AI: Definition, How It Works, and Applications

Agent-based AI refers to AI systems capable of pursuing a goal autonomously: they gather information, plan steps, take action within software, and adjust their plan based on the outcome. Definition, operation, risks, governance, and business applications.
September 24, 2026
Illustration: Protecting Your Small Business from Cyber Threats
Cybersecurity

How to Protect Your Small Business from Cyberattacks in 2026

Technical prevention, business continuity planning (BCP)/disaster recovery planning (DRP), and cyber insurance: the three lines of defense to protect your small business from cyberattacks in 2026.
September 24, 2026
Processing Electronic Invoices Using an AI Accounting Agent
Development & automation

AI Accounting Agent: What It Does with Electronic Invoices

Receiving electronic invoices will be mandatory starting in September 2026: what an AI accounting agent adds to your software, starting at what volume, and at what price.
September 23, 2026
AI illustration agent
Development & automation

AI Agents for HR: Use Cases, Legal Framework, and Deployment Methods

Onboarding, recruitment, HR questions: what an AI agent can handle, what the AI Act, the GDPR, and the Labor Code require, and how to measure it.
September 23, 2026
AI Help Desk Illustration
MSP & Managed IT Services: Proactive IT Management for Small and Medium-Sized Businesses

AI Help Desk for SMEs: 2026 Comparison of Solutions

Managed service with an AI agent or AI-powered help desk software: two categories, two pricing models. Comparison of Helpy (IT Systèmes), Witivio, Freshservice, Zendesk, and Moveworks; prices as of September 2026.
September 17, 2026