Brevo

Brevo

CRM and marketing automation for SMEs

Overview

Brevo is a European leader in digital marketing software that helps businesses manage customer relationships and grow sustainably. It offers a CRM and marketing tools to build personalized connections, with features for email marketing, automation, and transactional messaging, all accessible through a platform available in six languages. A forever free plan makes the core tools accessible to small and medium-sized enterprises, while Brevo Academy provides digital marketing training and onboarding. Enterprise plans include dedicated success managers and guided onboarding, with premium service options that add features and support. The company differentiates itself by its multilingual, SMB-friendly platform, a no-cost entry tier, and emphasis on guided training and personalized assistance. Its goal is to empower clients with comprehensive marketing tools and tailored support to foster client growth and a positive social impact.

About Brevo

Simplify's Rating
Why Brevo is rated
C-
Rated C on Competitive Edge
Rated C on Growth Potential
Rated D+ on Differentiation

Industries

Data & Analytics

Consumer Software

Enterprise Software

Company Size

501-1,000

Company Stage

Private

Total Funding

$404.5M

Headquarters

Paris, France

Founded

2012

Get referred to Brevo

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Brevo reported 500,000 customers and roughly $150 million ARR in 2024.
  • Oakley says new capital accelerates U.S. growth and intensified M&A.
  • Enterprise traction remains real: AXA, Michelin, LVMH, and Trezor already use Brevo.

What critics are saying

  • September 10, 2026 SAML flaw exposed 138 accounts and sent phishing to 347,000 Trezor users.
  • September 14, 2026 Cloudflare key abuse injected ClickFix malware into Brevo and 100,000 sites.
  • Trust collapse after two breaches and possible buyer diligence delays threaten enterprise renewals and exit timing.

What makes Brevo unique

  • Brevo's freemium CRM and marketing suite targets SMBs across 200+ countries.
  • Google Wallet Premium Partner status gives Brevo privileged loyalty and pass distribution integration.
  • Management backed by Oakley Capital and General Atlantic, funding AI and U.S. expansion.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$404.5M

Above

Industry Average

Funded Over

7 Rounds

Secondary funding comparison data is currently unavailable. We're working to provide this information soon!
Secondary Funding Comparison
Coming Soon

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Parental Leave

401(k) Company Match

Flexible Work Hours

Hybrid Work Options

Professional Development Budget

Bi-Annual Global Team Building Trip

Growth & Insights and Company News

Headcount

6 month growth

2%

1 year growth

2%

2 year growth

2%
NorriWire
Sep 16th, 2026
Weekly Brief 16.09.2026: Brevo leak affects trezor.

Weekly Brief 16.09.2026: Brevo leak affects trezor. Weekly brief for the Baltics and Northern Europe: A leak from the Brevo email platform (10-11 September) triggered a wave of phishing attacks targeting Trezor and BitBox hardware wallet users. Toms Ābeltiņš No new, clearly dated events in its segment over the past 24 hours. The main event of the week (10-11 September): A leak from the Brevo email platform triggered a wave of phishing attacks targeting Trezor and BitBox hardware wallet users; email addresses were affected, not devices or seeds. Wednesday, 16 September 2026. This is a 'Weekly Brief' format publication. Over the past 24 hours, there have been no new, clearly datable significant events in its segment - crypto exchanges and CASPs, hardware wallets, crypto cards, and tax tools serving the Baltics (LV, LT, EE) and Northern Europe (FI, SE, NO, DK). Therefore, today NorriWire offer a weekly overview with precise dates. The most clearly datable segment event of the week, not yet covered in its previous releases, is the wave of phishing attacks against hardware wallet users, publicised on 10-11 September, stemming from a security incident at the email marketing platform Brevo. Older, ongoing stories are presented as context, not as fresh news. Main event of the week: Brevo leak and phishing wave against hardware wallet users. On 10 and 11 September, several hardware wallet manufacturers warned customers about fraudulent emails impersonating official communications. The incident originated from a security leak at the email and newsletter platform Brevo (formerly Sendinblue). This event falls into the second category of its segment - hardware wallets - and partly into the fourth category, tax and portfolio tools, and is directly relevant to self-custody users in the Baltics and Nordics. According to Brevo's explanation, attackers gained access to approximately 120-140 customer accounts on the platform (various sources cite between approximately 120 and 138 accounts) due to insufficiently restricted access rights, and used these accounts to send phishing emails to the contact databases of the respective companies. In Trezor's case, approximately 347,000 fraudulent emails were sent. One of the recorded phishing emails used the subject line "Critical Security Alert: STM32 Entropy Vulnerability" and urged recipients to follow external links. Hardware wallet manufacturer BitBox confirmed using the same newsletter provider: the company stated that "it seems we all share the same newsletter provider", contacted the service provider, reported the phishing domains, and noted that most links had already been removed. The same provider incident was also discovered around the same time by crypto tax and portfolio tracking tool CoinTracking, illustrating that the leak affected a broader range of crypto services, not just wallet manufacturers. It is crucial to emphasise the boundary: the devices themselves, wallets, or seed phrases were not compromised. Trezor announced that "none of its products, wallets, or account systems were affected by the incident", and that customer email addresses were compromised. For this very reason, the manufacturer warns that leaked email addresses may be reused in future phishing campaigns. Trezor's advice to users was unequivocal: do not click on links, never enter your wallet backup anywhere, and always confirm every action physically on the Trezor device. Context: supply chain leaks and attacks on the "human trust layer" (Reminder, not fresh news). These points are not news from the last 24 hours; NorriWire include them only for background, with precise previous dates. The September phishing wave fits into a broader theme this year, where attackers bypass the hardware device itself and target customer data stored with third-party service providers. In August, Trezor disclosed a separate incident with shipping fulfilment partner ShipMonk, affecting at least approximately 81,000 customers, revealing names, phone numbers, email addresses, and postal addresses. It is precisely such data that makes subsequent phishing attempts more convincing. NorriWire do not consider this incident as new in September; it is background explaining why users in the region are currently receiving unusually targeted fraudulent emails. This background also aligns with the year of hardware wallet security previously covered in its releases: BitBox's 17 August firmware patch (version 9.26.5), Coldcard (Coinkite)'s seed entropy incident in early August, and the discovery of the Trezor Safe 7 TROPIC01 chip laser attack (Ledger Donjon, 3 June). The distinction is important: the September event is not a device or firmware vulnerability, but a data leak at an email service provider, which translates into a social engineering risk. Practical recommendations for market participants. For self-custody users and retailers selling hardware wallets in the region, the practical course of action is relatively straightforward. Firstly, be cautious of any "security alert" email urging you to urgently click a link or enter a seed phrase; legitimate manufacturers never ask for a wallet backup. Secondly, every action should be physically confirmed on the device screen, rather than relying on email content. Thirdly, if a user's email has potentially been part of a leak, that address should be considered at permanently elevated phishing risk in the future. Fourthly, firmware and applications should only be updated from official sources (bitbox.swiss, trezor.io, and similar), not from email links. Regulatory and market background. On the regulatory side, no new MiCA CASP authorisations for Baltic or Nordic crypto exchanges have been publicly registered in the past week. The ESMA MiCA register continued to expand over the summer - after July updates, it contained more than approximately 294-309 CASP entries - but net growth is primarily driven by notifications from continental (especially German) credit institutions, not regional crypto exchanges. Finland's Finanssivalvonta reminds that the European regulatory framework for CASPs is fully complete, with the last ESMA guidelines entering into force on 28 July 2026; this is ongoing context, not fresh news. In Estonia, the previously covered insolvency process of zondacrypto operator BB Trade Estonia OÜ continues: the Harju County Court in Tallinn declared the company insolvent on 27 August (licence fully revoked on 29 June), and the deadline for submitting creditor claims is set for 27 October. NorriWire covered this story in more detail in a separate publication; here NorriWire mention it only as ongoing context and a point to watch. Brevo and supply chain leaks: NorriWire is monitoring for additional information on the number of affected accounts and whether other crypto service providers in the region (exchanges, tax tools, card issuers) have used the same supplier. zondacrypto / BB Trade Estonia: The creditor claims deadline of 27 October remains the key upcoming date. ESMA MiCA register: NorriWire is monitoring for upcoming updates regarding Baltic and Nordic firms. Norway's transitional regime: Following the end of the MiCA transition on 30 June, NorriWire is monitoring Finanstilsynet's progress with the authorisation status of local exchanges (Firi, K33, NBX, TÝR Markets). Sources.

Cryptoticker.io GmbH
Sep 15th, 2026
Waltio confirms Brevo breach touched its user emails: here is what to do now.

Waltio confirms Brevo breach touched its user emails: here is what to do now. Waltio has told users its Brevo account was accessed during the September breach that also hit Trezor and BitBox. Here is what was exposed. Published: 09/15/2026 French crypto tax platform Waltio has started emailing its users about a security incident at Brevo, the third party email provider it uses to send campaigns. The message is calm, carefully worded, and mostly reassuring. It is also the latest confirmation that the Brevo breach of early September has a longer guest list than anyone first thought. If you are a Waltio user, your tax reports are fine. Your email address may not be. And in crypto, an email address in the wrong hands is not a small thing. Hasheur investisseur chez Waltio, faisant de la pub et disant d'utiliser Waltio avec son lien ref qui finalement sert aux criminels pour les kidnappings | DPM Waltio was a suspect for one of them What did waltio actually tell its users? The notice, sent in French under the heading "Information relative à la sécurité de vos données personnelles", sets out four points. * First, no malicious emails went out from Waltio's account. Nothing was blasted to the contact list pretending to be Waltio. * Second, Brevo's analysis is still running. Brevo has not been able to confirm whether the intruder actually viewed or exported Waltio's contact list, only that unauthorised access to the account happened. * Third, the data at risk is thin. The only fields Waltio keeps inside Brevo are the email address tied to your Waltio account and, if you entered it voluntarily, your French department number. That is the two digit administrative region code used in France, so 75 for Paris, 13 for Bouches du Rhône, and so on. Useful for regional tax messaging, and not much else on its own. * Fourth, the blast radius stops at Brevo. Waltio says the tool holds no passwords, no API keys, no wallet addresses, no transaction history and no tax data. Logins and connected exchanges are untouched. Waltio also notes that Brevo now treats the incident as closed. How big was The Brevo breach? Bigger than one French startup. Brevo said an attacker got into around 120 to 138 customer accounts on 9 and 10 September before access was cut off. The company later attributed it to an authorisation flaw in its login and single sign on layer rather than a classic password leak, which meant the attacker could reach every organisation the compromised invited users were entitled to see. Brevo's own breakdown split the damage three ways: a handful of accounts were used to send phishing, several dozen had contact lists exported, and the large majority showed no activity at all. Waltio's "analysis in progress" language suggests it is sitting somewhere between the second and third bucket, and does not yet know which. The names already confirmed are a who's who of crypto: Trezor, BitBox, CoinTracking and Solana Mobile. Trezor got the worst of it. Roughly 347,000 newsletter subscribers received a fake security alert about an STM32 entropy vulnerability, pointing to an app that asked for their wallet backup. Trezor killed the domain at DNS level within twenty minutes, but around 2,500 people had already clicked. Why does this matter more for waltio than for other Brevo clients? Because Waltio has been here before, and much worse. In January 2026 the platform suffered a genuine intrusion into its own systems, not a vendor's. Attackers exfiltrated data tied to tax report generation, contacted the company demanding a ransom, and the Paris prosecutor's cybercrime unit handed the investigation to the Gendarmerie's national cyber unit. Waltio confirmed that email addresses, aggregated crypto balances and tax report data had been exposed, while passwords, API keys, wallet addresses and banking details had not. A file circulating on Telegram afterwards was reportedly used to target French crypto holders directly. That history changes the maths on this new incident. A standalone email address is low value. An email address that can be cross referenced against a leaked file showing roughly how much crypto you hold is a targeting list. France has had a grim run of kidnappings and home invasions aimed at crypto holders, and those cases start with exactly this kind of data stitching. So the correct reading of the Waltio notice is not "nothing happened". It is "one more identifier of yours may now be in circulation, and you should assume the attackers are patient". How do you spot A waltio phishing email? The Brevo attack worked precisely because the phishing came through legitimate infrastructure. Sender domain checks, DKIM, SPF, the usual tells, all of it looked correct on the Trezor emails. So domain inspection alone will not save you here. Judge the ask instead: * Any message asking for your seed phrase or wallet backup is fraud. Always. Waltio states plainly that it will never ask for a seed phrase, a password or a transfer of funds, by email or by phone. * Any message pushing you to download an application to "fix" or "verify" something is fraud. * Any message creating a deadline, a legal threat or a tax penalty scare is worth a second look. Tax angles are the obvious hook for a Waltio user list. * Never click through from the email. Type waltio.com yourself, or contact support directly at [email protected]. What should waltio users do right now? Nothing dramatic, but a few things are worth doing this week. Turn on two factor authentication on your Waltio account and on every exchange it connects to, using an authenticator app rather than SMS. Review and revoke any exchange API keys you no longer use, and confirm the ones you keep are read only. Change your Waltio password if you have reused it anywhere else. Consider running your address through a breach checker to see what else about you is already public. One structural note is hard to avoid. Crypto tax tools sit on the richest dataset in the entire ecosystem, a complete picture of who owns what and where it sits. DAC8 reporting obligations across the EU are pushing more of that data into more places, not fewer. The Waltio notice is a reminder that the weakest link is rarely the platform itself. It is the newsletter tool bolted onto the side of it. Keeping your keys off the internet entirely is still the strongest answer to any phishing campaign. The CryptoTicker shop stocks hardware wallets at shop.cryptoticker.io.

The Daily Hodl
Sep 13th, 2026
Solana Mobile suspends marketing email account after unauthorized access.

Solana Mobile suspends marketing email account after unauthorized access. A cryptocurrency phone maker is warning customers after suspending its third-party marketing email account over unauthorized access. Solana Mobile says the access happened during a wider security incident at email provider Brevo. The incident is part of a larger breach at Brevo that affected 138 customer accounts through a Security Assertion Markup Language Single Sign-On (SAML SSO) vulnerability. Says Solana Mobile, "Our third-party marketing email provider, Brevo, experienced a security incident affecting some customer accounts, including Solana Mobile. We identified unauthorized access to our Brevo account, disabled the account, and are working with Brevo to understand the scope of information accessed. To our knowledge, no emails were sent from the Solana Mobile account, but we are continuing to verify with Brevo. A reminder that Solana Mobile will never ask for your seed phrase, private keys, or wallet recovery details." Solana Mobile builds crypto-focused smartphones for the Solana ecosystem. Meanwhile, Brevo says that a handful of customer accounts were used for malicious purposes. "Six of those accounts were used to send phishing emails to the contacts stored there, and for 43 accounts, they exported the contacts. 93 accounts have no meaningful activity. The attacker no longer has access... These messages were sent through legitimate infrastructure, so they passed the usual email authentication checks and looked genuine. The Daily Hodl has disabled all links in those emails, but as a preventive measure, please do not click them. Customers trust The Daily Hodl with access to their audiences, and in this case The Daily Hodl failed to protect it." Follow The Daily Hodl on X, Facebook and Telegram Don't Miss a Beat - Subscribe to get email alerts delivered directly to your inbox Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any assets including cryptocurrencies, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing. Generated Image: Midjourney

NorriWire
Sep 13th, 2026
Trezor and BitBox phishing 13.09.2026: Brevo leak.

Trezor and BitBox phishing 13.09.2026: Brevo leak. Daily Brief for the Baltic and Nordic segment: An incident involving email service Brevo led to ~347,000 phishing emails being sent to Trezor and BitBox customers from an authentic domain. Context provided on the ShipMonk leak and watchlist items. Toms Ābeltiņš Over the past 24-48 hours, its segment has seen one clearly datable major event: an incident with email marketing platform Brevo between 9-11 September resulted in a massive phishing campaign targeting Trezor and BitBox hardware wallet customers from a legitimate domain. Context provided on the ShipMonk leak and watchlist items. Sunday, 13 September 2026. This is a condensed (slim) version of the Day Brief, including a watchlist. Over the past 24-48 hours, its segment - crypto exchanges and CASPs, hardware wallets, crypto cards, and tax tools serving the Baltics (LV, LT, EE) and Northern Europe (FI, SE, NO, DK) - has experienced one clearly datable major event: a widespread phishing campaign targeting customers of hardware wallet manufacturers Trezor and BitBox, triggered by a security incident at the email marketing service Brevo. There have been no new regulatory developments directly in its region during this timeframe; ongoing stories are covered in the watchlist with precise previous dates, rather than being repeated as fresh news. Brevo incident: phishing wave from a genuine Trezor domain. On 9 September, hardware wallet manufacturer Trezor publicly warned that its customers were receiving fraudulent emails with the subject line "Critical Security Alert: STM32 Entropy Vulnerability". The messages originated from the company's legitimate domain ([email protected]) and contained valid signatures, making them harder to identify than typical fake mailings. Trezor emphasised that this email was not from the company and was a phishing attempt. On the same day, similar emails were reported by Swiss hardware wallet manufacturer BitBox (fake subject line "Critical Security Alert: Microcontroller Entropy Bug Identified"), as well as crypto tax and portfolio tracking service CoinTracking. The common cause is a security incident at the email marketing platform Brevo (formerly Sendinblue), which Brevo confirmed. On 11 September, Trezor clarified the scope of the incident in a blog post: according to the company, attackers gained access to approximately 138 Brevo accounts and sent around 347,000 phishing emails to Trezor customers (Brevo's earlier communication mentioned approximately 120 affected accounts). In all cases, the messages attempted to persuade the recipient to enter or disclose their wallet recovery phrase (seed) - precisely what should never be done. Important: the "entropy vulnerability" mentioned in the emails is a lure used by scammers, not a real defect in Trezor or BitBox devices. Trezor states that its own systems, products, and services have not been affected - the leak occurred with a third-party supplier - and that the company is re-evaluating relationships with its suppliers. In interpreting this, it's worth distinguishing two levels: the fact is the compromise of an email delivery channel and mass phishing; the assertion that devices remain secure, however, is the manufacturer's position, which in this case aligns with the nature of the incident - a marketing sending platform was affected, not the cryptographic device itself. Why this is important for the region: Trezor and BitBox are among the most common hardware wallets in the Baltics and Nordics, so the campaign poses a direct risk to users in this region. The danger of the attack is amplified by the fact that the messages come from an authentic domain and use technically plausible "security alert" phrasing. Recommendations for users in the Baltics and Nordics. Do not open or click on links in such "security alert" emails, even if the sender's address appears authentic. Never enter your wallet recovery phrase (seed) online, in any form, or at the request of an email, call, or text message - no legitimate manufacturer will ever ask for it. Verify any "vulnerability" notification only through the official Trezor or BitBox blog and approved social channels, not via a link received in an email. Expect further phishing and voice phishing (vishing) attempts, as affected email addresses may be reused. Context: ShipMonk delivery partner leak (reminder, not fresh news). This is not news from the last 24 hours, but it explains why phishing is so plausible right now. Trezor announced a data leak at its logistics partner ShipMonk around 10 August, initially affecting approximately 13,700 customers. On 4 September, the company updated the information: older data (from November 2019 to August 2021) was additionally discovered, affecting another approximately 67,000 US customers, bringing the total to around 80,700 customers. The exposed data included names, addresses, phone numbers, and emails. ShipMonk handled Trezor deliveries to Sweden, among other places, which is a direct link to the Nordic market. Trezor also emphasises in this case that devices are secure and no Trezor system has been affected. Two third-party incidents within a month (ShipMonk and Brevo) together form the context for the current wave of phishing. Hardware wallet entropy as a lure: previous real events - the Coldcard (Coinkite) seed entropy incident in August and the Trezor Safe 7 / TROPIC01 chip laser attack research (Ledger Donjon, 3 June) - make fake "entropy vulnerability" warnings more credible. These are older events, not new news, but they explain the phrasing chosen by scammers. ESMA MiCA Register: NorriWire continue to monitor whether Baltic and Nordic CASPs are joining the register. NorriWire did not detect any new regional firms joining during this timeframe; the next register update remains the main structural indicator for its segment. Vendor risk: Two third-party incidents in a short period highlight the importance of supply chain and marketing tool security in the hardware wallet industry. This is a topic NorriWire will keep an eye on regarding regional exchanges and card issuers who use similar external services. Summary for market participants. Key practical conclusion for users: treat any email asking to "verify" or enter a wallet recovery phrase as a scam, regardless of the sender's address. An authentic domain is no longer a guarantee of trustworthiness. For hardware wallet and exchange partners in the region: review which external services (email sending, logistics, support tools) store customer data, as this year's incidents show that the greatest risk comes from the supply chain, not the devices themselves. Distinguish facts from positioning: mass phishing and data leaks are confirmed facts; the statement "devices remain secure" is the manufacturer's position, which in this case is consistent with the nature of the incident, but which should always be evaluated separately. Keep an eye on the next ESMA register update - the movement of regional CASP authorisations remains the most important structural indicator for its segment in the coming weeks. Sources.

OXO
Sep 12th, 2026
Trezor: 347,000 users targeted in phishing attacks after Brevo breach.

Trezor: 347,000 users targeted in phishing attacks after Brevo breach. September 12, 2026 · by 0x0 · News If you're a Trezor user, this is likely your problem. Trezor disclosed that 347,000 of their users were targeted in phishing attacks after a breach at Brevo, with 2,500 users clicking on a malicious link. I see this pattern in many crypto wallet breaches - the attackers often use phishing as a way to get users to divulge sensitive information or install malware. In this case, the phishing attacks were sent to users via email, which is a common vector for these types of attacks. Honestly, the fact that only 2,500 users clicked on the malicious link seems like a relatively low number, given the large number of users targeted. However, it's still a significant issue, as those 2,500 users may have had their wallets compromised or installed malware on their devices. As a sysadmin, I've seen firsthand how quickly phishing attacks can spread and cause damage. The Brevo breach is likely the source of the email addresses used in the phishing attacks. I've dealt with similar breaches in the past, where an attacker gains access to a large list of email addresses and uses them to launch targeted phishing attacks. In this case, the attackers seem to have been fairly successful, with 2,500 users falling victim to the phishing attacks. If you're a Trezor user, you should be on high alert for phishing attacks. Check your email inbox for any suspicious emails, and be cautious of any links or attachments from unknown senders. I always recommend using a hardware wallet like Trezor, but it's equally important to be vigilant about phishing attacks. To check if you've been targeted, you can try searching your email inbox for any suspicious emails. You can also try contacting Trezor support to see if your account has been affected. Action: Change your Trezor account password and enable 2-factor authentication as soon as possible.

Recently Posted Jobs

Sign up to get curated job recommendations

Brevo is Hiring for 25 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →