French crypto platform Paymium notified its customers on September 22 that unauthorized access had occurred at its email router, provided by Brevo. The exchange said the exposed data included email addresses, account IDs, first and last names, dates of birth, phone numbers and countries of residence.

Paymium said no passwords, API keys, wallet data or tax information were exposed, and that no funds had been moved from customer accounts. The company directed affected clients to cybermalveillance.gouv.fr, the French government's public cybersecurity assistance service, for further guidance.

The incident traces back to a vulnerability in Brevo's single sign-on system, which allowed an attacker to open accounts across 138 client companies. According to Brevo, the attacker created their own account, connected an identity provider under their control, invited legitimate users, and then logged in posing as them. The breach was detected on September 10 at 6:30 UTC and patched roughly two hours later.

Of the 138 compromised client accounts, 43 had their contact lists exported, and six were used to send phishing emails. One of those six accounts was used to send a fake security alert to approximately 347,000 subscribers of hardware wallet maker Trezor, generating around 2,500 clicks on the fraudulent message.

Part of a wider pattern

Paymium's disclosure follows similar incidents earlier in September affecting Trezor, BitBox and CoinTracking, all of which relied on Brevo for email services. The cluster of breaches has renewed scrutiny of third-party service providers used across the crypto industry, where a single vulnerability can cascade across multiple platforms holding sensitive customer information.

Data leaks involving crypto customers have carried physical consequences before. In December 2020, postal addresses belonging to more than 270,000 Ledger customers were leaked on a hacker forum, followed by threats against affected individuals. More recently, French judicial police recorded 41 kidnappings or unlawful detentions linked to cryptocurrencies in France between January 1 and mid-April 2026, underscoring the stakes attached to any exposure of personal information tied to crypto holdings.

Paymium has not disclosed how many of its clients were affected by the Brevo breach, nor whether its account fell among the 43 with exported contact lists or the six used for phishing. The company's notification focused on the categories of data involved and reassurance that financial credentials and funds remained untouched.