Paymium notified its customers on September 22 that an unauthorized access at its email service provider Brevo had exposed their personal data: identity, date of birth, phone number and country of residence. The breach originated from an SSO flaw allowing an attacker to impersonate legitimate users and access 138 client accounts, of which 43 had their contact lists exported and 6 were used to send phishing emails. No passwords, API keys or financial data were compromised according to the platform. The exact number of affected customers was not disclosed.
Source: Read the original article

