In September 2026, Brevo, a service provider used by Paymium to send certain email communications, was the victim of a security incident that allowed an attacker to access several customer accounts on its platform.
This incident affected the Brevo account used by Paymium and resulted in the extraction of personal data stored there.
We would like to factually review the circumstances of this incident, its scope, the data concerned, and the measures taken.
What happened at Brevo?
On September 10, 2026, at 6:30 AM UTC, Brevo identified a flaw affecting its SAML-based Single Sign-On (SSO) authentication system.
According to information published by Brevo, an attacker created a Brevo account, enabled an SSO configuration, and then invited legitimate Brevo users to join this configuration.
A security limitation that should have restricted this access to a single organization was not properly enforced. The attacker was thus able to access other organizations to which these users themselves had access.
Brevo indicates that 138 customer accounts were affected:
- on 6 accounts, access was used to send phishing emails;
- on 43 accounts, contact lists were exported;
- on 93 accounts, Brevo indicates having identified no significant activity by the attacker.
At 8:30 AM UTC on September 10, Brevo reported closing the exploited access path and resetting active user sessions. Brevo specifies that no further activity from the attacker via this route has been observed since this intervention.
What data was extracted?
In the context of this incident, all data stored in Paymium's Brevo environment was extracted.
The information present in Brevo could include:
- email address and identifier associated with the Paymium account;
- last name;
- first name;
- date of birth;
- phone number;
- country of residence.
However, not all of this information was provided for every contact. The level of information available varied depending on the person: some records might, for example, contain only an email address, others an email address and phone number, while others included all or part of the information listed above.
The incident concerned only our provider Brevo's environment and did not affect Paymium's infrastructure, nor did it grant direct access to our customers' accounts or assets.
To our knowledge, no fraudulent or malicious emails were sent from Paymium's Brevo account as part of this incident.
What measures were taken?
Following the detection of the incident, Brevo indicated having closed the access path used by the attacker and logged out all active sessions across its platform.
Brevo also announced the deployment of a patch to strictly restrict SSO connections to the owner organization of each SSO configuration. The company further indicated having initiated proceedings with authorities and cooperating with them.
On our end, access security related to our Brevo environment has been reinforced.
Paymium informed its customers about the incident and its scope.
Vigilance against phishing attempts
The extracted data consists of identity and contact details. They may be used to make phishing attempts by email, SMS, or phone appear more credible.
We therefore recommend that our customers remain particularly vigilant regarding any communication referencing Paymium or crypto-assets.
As a reminder, Paymium will never ask you, whether by email or phone, to share your password, seed phrase, or private keys, nor to transfer funds as part of a security procedure.
If you have any doubt about a communication received in the name of Paymium, do not click on any links and contact our customer service directly at [email protected]
Always make sure to log in using the URL: account.paymium.com
Transparency and Information
Protecting our customers' data and assets is a top priority for Paymium.
When an incident affecting one of our service providers involves user data, our responsibility is to determine its precise scope, take necessary measures, and inform our customers based on available information.
We will continue to communicate transparently if new details regarding this incident are established.




