decrypted · 11 september 2026 · ransomware and cybercrime · vulnerabilities and patching · supply chain

The SSO flaw that let one attacker log in as 138 companies

A flaw in how the email marketing platform Brevo checks single sign-on logins let one attacker create their own account, invite real customers of unrelated Brevo tenants into it, and inherit their access across organisations that had nothing to do with each other. The attacker used that access to email fake security alerts through the accounts of hardware wallet maker Trezor and two peers, CoinTracking and BitBox, warning of a fictitious chip vulnerability and pointing recipients at a phishing site. Roughly 347,000 people received the message before Trezor pulled the malicious domain twenty minutes after detection, with about 2,500 having clicked through. It is a smaller, cleaner echo of the story this section covered on Wednesday, where a UK airport group's admin keys for its own customer engagement platform had been sitting in public view for four years. Different vendors, same category of mistake: a system built to talk to customers on a company's behalf turns out to hold far more trust than anyone had checked.

A front desk with a spare master key

Brevo lets any customer switch on SSO for their account, then sign in via their chosen identity provider. The attacker set up their own Brevo account, turned on SSO for it, and invited real users from other companies' Brevo accounts into that configuration using an identity provider they controlled. Brevo's checks then let those users log in as themselves, correctly, but did not confine the resulting access to the attacker's own account. It is as if a hotel let any guest open a side desk, invite guests staying at other hotels to check in through it, and then honoured whatever room key those guests already held anywhere in the chain, because nobody had coded the desk to check which building it actually belonged to. Brevo says the access has been closed off: 138 accounts were reachable, contact lists were pulled from 43 of them, and six were used to send the phishing run.

The Secure by Design lesson

Single sign-on exists to narrow trust to one identity boundary. This bug widened it, because the system verified who a user was without verifying which tenant they were allowed to act for on that particular login. That is the specific, fixable design gap: authorisation has to be scoped per tenant on every request, not inferred once at sign-in and assumed to travel safely afterwards. It is the same category of failure as Manchester Airports Group's exposed keys, just one layer further from the customer, and it should prompt the same question from any UK organisation that plugs a marketing, CRM or customer engagement tool into its stack: audit what a malicious tenant of that vendor could reach if they simply signed up, because that is now part of your attack surface, not the vendor's problem alone.

Also this week

Adobe's Magento zero-day, CVE-2026-75650, now has a patch. The flaw, a maximum-severity CVSS 10.0 bug in Magento's template handling, has been under active exploitation since 4 September, with attackers deploying a Rust-based Linux backdoor and PHP web shells through it. Adobe's hotfix, VULN-39341, is live on repo.magento.com and also requires rotating encryption keys, not just applying the patch. CISA's federal deadline for fixing it lands today, 11 September; any UK retailer running Magento or Adobe Commerce should treat that as their deadline too, if they haven't already moved.

Manchester Airports Group has confirmed it refused to pay the ransom demanded by the group that leaked roughly 550GB of data on 8.8 million customers. MAG maintains this was "a hack, not a lapse," describing the intrusion as sophisticated, a characterisation the airport group has not reconciled with the four years its admin keys spent sitting in public JavaScript. Nothing about the underlying breach has changed since Wednesday; what's new is that the ransom question is now settled and MAG is contesting how the story gets told.

Sources

Rethinking what your marketing or customer engagement stack can actually reach? Get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.