Brevo Hacking: After Trezor, Paymium Customer Data Leaked

By: journalducoin.com|2026/09/23 04:50:22

New collateral victim. After the fake emails from Trezor, it's now the turn of Paymium customers to discover that their identity details may have slipped through the back door. The French platform notified its users on September 22. Its email service provider Brevo had already served as a launchpad for the phishing campaign against Trezor, BitBox, and CoinTracking in early September. No funds have been moved. But a file of identified crypto holders is worth its weight in gold amid a wave of kidnappings.

Key Points

  • Paymium warned its customers on September 22 of unauthorized access to its email router
  • Identity, date of birth, phone number, and country of residence are included in the leak
  • No passwords, API keys, or access to funds according to the platform
  • At Brevo, 138 customer accounts were opened due to a single sign-on vulnerability

Paymium Data Leak, the Bill Arrives Twelve Days Later

The message lands in inboxes twelve days after the events. Paymium explains that Brevo, the tool managing part of its mailings, suffered an intrusion. According to the notification relayed by FrenchBreaches, the intruder was able to view the email address, account ID, first name, last name, date of birth, phone number, and country of residence of the affected customers. How many are there? The platform does not disclose.

On the reassuring side, the list of what has not leaked is long. No passwords, no API keys, no wallet data, or tax information was transmitted through Brevo, assures Paymium. No fraudulent emails would have been sent from its account.

🔴 Paymium confirms a data leak: the French cryptocurrency platform was affected via its provider Brevo.

Personal data of customers may have been accessed, but no passwords, crypto assets, wallets, or API keys are involved. https://t.co/W2GYY9XH9w pic.twitter.com/WXhm38ggeE --- Seb (@seblatombe) September 22, 2026

Brevo, a SSO Vulnerability as Big as a Barn Door

It all starts with an acronym, SSO (single sign-on that allows connecting to multiple services with a single identifier). The incident report published by Brevo describes an almost vexing scenario. The attacker opens their own account, connects an identity provider they control, then invites legitimate users. They then log in on their behalf. And the access thus obtained, poorly compartmentalized, was not limited to one organization but extended to all those that these users could reach.

Spotted on September 10 at 6:30 AM (UTC), the breach was patched two hours later. Of the 138 customer accounts accessed, 43 had their contact lists exported and six were used to send phishing emails. Paymium does not specify which group it falls into.

It is from one of these six accounts that nearly 347,000 Trezor subscribers received a false security alert, with about 2,500 clicks resulting.

Leak at Paymium, a File that Makes Scammers Salivate

Regulated platforms must verify the identity of their clients (the famous KYC). They also need to write to them, often entrusting this chore to a subcontractor. Your date of birth and mobile number thus rest with a third party you never chose. The cocktail has everything to please a scammer. They know you hold cryptos, in which country you live, how to call you, and how old you are, enough to set up a fake call from the "Paymium security service" that is credible enough to deceive.

The previous Ledger incident has not lost its relevance. In December 2020, the postal details of over 270,000 customers of the manufacturer ended up on a hackers' forum, followed by a barrage of threats. Here, there is no postal address. But France in 2026 is no longer a theoretical ground for the physical targeting of crypto holders.

Paymium Customers, Reflexes to Adopt After the Leak

Paymium directs its customers to cybermalveillance.gouv.fr, the public free assistance service. Add a few reflexes that cost nothing.

  • Do not click on any links received by email or SMS in the name of Paymium, go through the app or type the address yourself
  • A "consultant" calling you to secure your account is an impostor, hang up
  • Never share your recovery phrase with anyone
  • Enable two-factor authentication if you haven't already

Between January 1 and mid-April 2026, the judicial police had already recorded 41 kidnappings or abductions related to cryptocurrencies on the territory. Nothing currently links these cases to a data leak. A date of birth, however, cannot be changed like a password.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com