Solana Mobile said attackers gained unauthorized access to its Brevo marketing account, potentially exposing customer information in a security incident at the email provider.
The company disabled its Brevo account after discovering the breach and is working with the provider to determine what data may have been accessed. Solana Mobile said it has no evidence that emails were sent from its account, but the review is continuing.
Brevo Breach Affects Crypto Firms
Brevo said attackers exploited a flaw in its SAML single sign-on system, gaining access to 138 customer accounts before the company blocked the intrusion.
Related: Government Seizure Is Not Victim Repayment: What Crypto Users Need to Know
The attackers exported contact lists from 43 accounts, while six accounts were used to send phishing emails. Trezor said the breach affected information linked to about 347,000 subscribers. BitBox and CoinTracking also reported attacks involving their Brevo accounts.
The phishing campaigns used malicious links designed to steal users’ login details. Rather than gaining direct access to crypto wallets, the attackers used contact information from the affected accounts to target subscribers.
Solana Mobile Issues Security Reminder
Solana Mobile urged users to remain cautious, stressing that it will never ask for seed phrases, private keys or wallet recovery details.
DeFi Warhol also pointed to recent Trezor-related attacks involving email and support providers. The incidents showed how stolen contact data can be used to target crypto users.
Related: Bitcoin Red Team Claims Blockstream Ignored Warnings Before Hack
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.