Brevo Hacking: After Trezor, Paymium Customer Data Leaked
New collateral victim. After the fake emails from Trezor, it's now the turn of Paymium customers to discover that their identity details may have slipped through the back door. The French platform notified its users on September 22. Its email service provider Brevo had already served as a launchpad for the phishing campaign against Trezor, BitBox, and CoinTracking in early September. No funds have been moved. But a file of identified crypto holders is worth its weight in gold amid a wave of kidnappings.
Key Points
- Paymium warned its customers on September 22 of unauthorized access to its email router
- Identity, date of birth, phone number, and country of residence are included in the leak
- No passwords, API keys, or access to funds according to the platform
- At Brevo, 138 customer accounts were opened due to a single sign-on vulnerability
Paymium Data Leak, the Bill Arrives Twelve Days Later
The message lands in inboxes twelve days after the events. Paymium explains that Brevo, the tool managing part of its mailings, suffered an intrusion. According to the notification relayed by FrenchBreaches, the intruder was able to view the email address, account ID, first name, last name, date of birth, phone number, and country of residence of the affected customers. How many are there? The platform does not disclose.
On the reassuring side, the list of what has not leaked is long. No passwords, no API keys, no wallet data, or tax information was transmitted through Brevo, assures Paymium. No fraudulent emails would have been sent from its account.
🔴 Paymium confirms a data leak: the French cryptocurrency platform was affected via its provider Brevo.
Personal data of customers may have been accessed, but no passwords, crypto assets, wallets, or API keys are involved. https://t.co/W2GYY9XH9w pic.twitter.com/WXhm38ggeE --- Seb (@seblatombe) September 22, 2026
Brevo, a SSO Vulnerability as Big as a Barn Door
It all starts with an acronym, SSO (single sign-on that allows connecting to multiple services with a single identifier). The incident report published by Brevo describes an almost vexing scenario. The attacker opens their own account, connects an identity provider they control, then invites legitimate users. They then log in on their behalf. And the access thus obtained, poorly compartmentalized, was not limited to one organization but extended to all those that these users could reach.
Spotted on September 10 at 6:30 AM (UTC), the breach was patched two hours later. Of the 138 customer accounts accessed, 43 had their contact lists exported and six were used to send phishing emails. Paymium does not specify which group it falls into.
It is from one of these six accounts that nearly 347,000 Trezor subscribers received a false security alert, with about 2,500 clicks resulting.
Leak at Paymium, a File that Makes Scammers Salivate
Regulated platforms must verify the identity of their clients (the famous KYC). They also need to write to them, often entrusting this chore to a subcontractor. Your date of birth and mobile number thus rest with a third party you never chose. The cocktail has everything to please a scammer. They know you hold cryptos, in which country you live, how to call you, and how old you are, enough to set up a fake call from the "Paymium security service" that is credible enough to deceive.
The previous Ledger incident has not lost its relevance. In December 2020, the postal details of over 270,000 customers of the manufacturer ended up on a hackers' forum, followed by a barrage of threats. Here, there is no postal address. But France in 2026 is no longer a theoretical ground for the physical targeting of crypto holders.
Paymium Customers, Reflexes to Adopt After the Leak
Paymium directs its customers to cybermalveillance.gouv.fr, the public free assistance service. Add a few reflexes that cost nothing.
- Do not click on any links received by email or SMS in the name of Paymium, go through the app or type the address yourself
- A "consultant" calling you to secure your account is an impostor, hang up
- Never share your recovery phrase with anyone
- Enable two-factor authentication if you haven't already
Between January 1 and mid-April 2026, the judicial police had already recorded 41 kidnappings or abductions related to cryptocurrencies on the territory. Nothing currently links these cases to a data leak. A date of birth, however, cannot be changed like a password.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

What is Fin.com? Understanding Cross-Border Payment Infrastructure via API

Proposal to Expropriate Digital Assets in Special Cases

Circle Foundation launches first U.S. grants for AI

Uniswap (UNI) Price Jumps Toward $10 as CME Futures Launch Nears: What Traders Need to Know

The Surge of AVAX: 'Wall Street on the Chain' Becomes the New Main Line

XRPL fixes critical pre-mainnet flaw, but client apps remain at risk

CME Plans BCH and UNI Futures on October 19 | WEEX TradFi Daily Brief (September 23, 2026)
Global markets on September 23 focus on a Nasdaq high and an expansion of crypto futures. The Nasdaq closed higher on September 22 for a second straight closing high. Memory names such as Micron and SanDisk plus AI hardware lifted risk appetite. Brent eased to about $98 and WTI to about $94.6. Bitcoin was near $86,200 and Ethereum near $2,750. Investors are watching CME’s planned October 19 BCH/UNI futures and the impact of delayed compute-futures review on NVDA and CME.

Kakao Pay and Kakao Bank Partner with Fireblocks to Begin Verification of KRW Stablecoin Project

On the Same Day, Three Conditional Approvals: OCC Standardizes Stablecoin Bank Licensing

U.S. Treasury Secretary Scott Bessent: The U.S. dollar still accounts for 89.2% of global foreign exchange trading! Stablecoins are merely a digital extension of dollar hegemony

Bernstein Research Report: Why Can Gold Still Surge to $5,700 Even with Continued Rate Hikes by the Fed?

Masayoshi Son is borrowing money again, betting billions on OpenAI

Cryptocurrencies Will 'Devour' AI, Says Cardano Founder

Coinbase, Ripple, and a16z Fund Plan to Revive Clarity After Its Failure

Pi Network KYC and wallet fixes target over 900,000 users

Inside Coinbase’s $250 Billion Playbook for Post-Quantum Bitcoin Custody

The IMF opens an office in Venezuela to supervise an economy that has already migrated to USDT

Changes in SAS, crypto, and activity definition: the Government eases procedures to open a business

Zcash's shielded activity reached a four-year high

MicroStrategy CEO Says Jamie Dimon Is a Bitcoiner Behind the Scenes

The Link Between Bitcoin and Stocks Strengthened by ETF Effects

Trump Rejects Global AI Regulation at UN, Vows Not to Stifle Growth

Crypto: Russia Expects 10 Million New Users by 2027

MERGE Madrid 2026: Institutional Crypto Settles in Madrid

Prometheum details ownership rights for tokenized US stocks

Geo launches TikTok-style debates with CLARITY Act face-off

Nephos, Brinc bring crypto compliance support to GCC startups

Crypto firms still face full AML rules after CLARITY Act vote

Discord Cointribune: The New Crypto Hub of France?
