Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now

NewsTue, 15 Sep 2026 14:53:02 UTC5 hours ago
Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now

French crypto tax platform Waltio has started emailing its users about a security incident at Brevo, the third party email provider it uses to send campaigns. The message is calm, carefully worded, and mostly reassuring. It is also the latest confirmation that the Brevo breach of early September has a longer guest list than anyone first thought.

If you are a Waltio user, your tax reports are fine. Your email address may not be. And in crypto, an email address in the wrong hands is not a small thing.

What Did Waltio Actually Tell Its Users?

The notice, sent in French under the heading "Information relative à la sécurité de vos données personnelles", sets out four points.

  • First, no malicious emails went out from Waltio's account. Nothing was blasted to the contact list pretending to be Waltio.
  • Second, Brevo's analysis is still running. Brevo has not been able to confirm whether the intruder actually viewed or exported Waltio's contact list, only that unauthorised access to the account happened.
  • Third, the data at risk is thin. The only fields Waltio keeps inside Brevo are the email address tied to your Waltio account and, if you entered it voluntarily, your French department number. That is the two digit administrative region code used in France, so 75 for Paris, 13 for Bouches du Rhône, and so on. Useful for regional tax messaging, and not much else on its own.
  • Fourth, the blast radius stops at Brevo. Waltio says the tool holds no passwords, no API keys, no wallet addresses, no transaction history and no tax data. Logins and connected exchanges are untouched. Waltio also notes that Brevo now treats the incident as closed.

How Big Was The Brevo Breach?

Bigger than one French startup. Brevo said an attacker got into around 120 to 138 customer accounts on 9 and 10 September before access was cut off. The company later attributed it to an authorisation flaw in its login and single sign on layer rather than a classic password leak, which meant the attacker could reach every organisation the compromised invited users were entitled to see.

… Continue reading the full article at the original source below.

Read from Source · cryptoticker.io ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptoticker.io).

Related