An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields.
The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms.
Brevo initially said an attacker had gained access to 120 customer accounts, some of which were used to send phishing emails to the customers’ contact lists.

Brevo later said 138 customer accounts had been accessed in its postmortem:
“On September 10th at 6:30 AM UTC we identified a security issue where an attacker exploited a flaw in the way Brevo…







