Brevo Security Flaw Let Attacker Access 138 Customer Accounts

Email and marketing platform Brevo in an advisory has said an attacker gained access to 138 customer accounts after exploiting a flaw in the way its single sign-on system handled access between organizations.

Brevo identified the security issue on September 10. According to the company, contacts were exported from 43 affected accounts, while six accounts were used to send phishing emails to stored contacts. Brevo says 93 accounts showed no meaningful attacker activity.

The company says the attacker no longer has access and that affected customers are being contacted directly.

Flaw Involved Brevo’s SAML Single Sign-On System

The issue involved SAML SSO, a sign-in method commonly used by organizations to let employees access services using their existing company credentials.

According to Brevo, the attacker created an account and configured SSO before inviting legitimate Brevo users into that configuration. The attacker could then sign in as those users through an identity provider they controlled.

The problem was that the resulting access was not limited to the organization where that SSO configuration had been created.

Instead, Brevo says the attacker could also reach other organizations those users were authorized to access.

Brevo described the underlying problem as a failure to properly enforce the boundary between organizations using SSO.

The attacker used six compromised accounts to send phishing messages to contacts stored in Brevo.

Because those emails were sent through legitimate Brevo infrastructure, the company says they passed normal email authentication checks and could appear genuine to recipients.

Brevo says it has disabled the links contained in those messages and is advising recipients not to click them.

Contacts were also exported from 43 affected accounts, although Brevo has not publicly detailed what information was contained in each export.

Brevo says it closed the route used by the attacker at 8:30 a.m. UTC on September 10, approximately two hours after identifying the issue.

The company also signed out every user on its platform by resetting all active sessions. Brevo says it has observed no further attacker activity since then.

A permanent fix is being deployed to ensure that SSO access is limited to the organization that owns the configuration.

Brevo says it is contacting every affected customer with information specific to their account and has filed a legal complaint over the incident.

Customers who received suspicious messages sent through Brevo during the incident should avoid clicking links in those emails, even if the messages appear to have passed normal email authentication checks.