Solana Mobile says it has suspended its account with marketing email provider Brevo after detecting unauthorized access during a broader security incident at the vendor. The company said it is still working with Brevo to determine what information, if any, was accessed.

The disclosure came as Brevo described a wider breach tied to a Security Assertion Markup Language single sign-on vulnerability. Brevo said 138 customer accounts were affected in total, with a smaller subset used to send phishing emails or export stored contacts.

Solana Mobile says account was disabled

In a notice to customers, Solana Mobile said Brevo, its third-party marketing email provider, suffered a security incident that affected some customer accounts, including its own. Solana Mobile said it identified unauthorized access to its Brevo account and disabled the account after discovering the issue.

The company added that it is working with Brevo to understand the scope of the incident and what data may have been viewed or accessed. Solana Mobile said that, to its knowledge, no emails were sent from its Brevo account, but that point is still being verified with the provider.

Solana Mobile also repeated a common safety warning for crypto users, saying it will never ask customers for a seed phrase, private keys, or wallet recovery details.

Brevo links incident to SAML SSO flaw

According to Brevo, the broader breach involved 138 customer accounts and was connected to a vulnerability in SAML SSO, a system commonly used for centralized account access. The company said the attacker no longer has access.

Brevo broke down the activity across the affected accounts. It said six accounts were used to send phishing emails to contacts stored in those accounts, while 43 accounts had contact data exported. For the remaining 93 accounts, Brevo said it found no meaningful activity.

Phishing emails appeared legitimate

Brevo said the phishing messages sent from the compromised accounts went through legitimate infrastructure, allowing them to pass normal email authentication checks and appear genuine. The company said it has disabled all links contained in those emails and advised recipients not to click them as an added precaution.

That detail is significant because messages that pass standard authentication checks can be harder for recipients and mail systems to distinguish from routine company communications. Brevo acknowledged the seriousness of the failure, saying customers trust it with access to their audiences and that it did not protect that access in this case.

What is confirmed so far

At this stage, Solana Mobile has confirmed unauthorized access to its Brevo marketing account, but it has not reported any confirmed emails sent from that account. The company is still verifying the extent of the exposure with Brevo.

The next confirmed step is the ongoing investigation between Solana Mobile and Brevo to determine the scope of accessed information. Until that review is complete, the company’s warning centers on caution around any unexpected requests for wallet credentials or recovery information.

Source: dailyhodl.com