← All issues

This Week In Email — September 23, 2026

A trusted ESP got its SSO scoping wrong and 347,000 Trezor subscribers paid for it. A hacked Italian government mailbox talked Revolut into handing over passport scans on 680 crypto whales. Microsoft is squeezing both ends of the Exchange pipe at once. And 82% of U.S. campaign domains are still sitting on p=none seven weeks out from the midterms.

In This Issue

It's a heavy one, and the through-line is ugly: almost every major security story this week involves fully authenticated, legitimately-sent mail. SPF passed. DKIM passed. DMARC passed. The attackers didn't spoof anything — they got inside infrastructure senders and recipients already trusted and rode it. Let's get into it.

Top Stories

Brevo's SSO Flaw Let an Attacker Phish 347K Trezor Subscribers Through 138 Hijacked Accounts

An attacker created their own Brevo organization, turned on SSO, and invited legitimate users into it. Because access wasn't scoped to the org SSO was actually configured for, those invited accounts could reach every other org the invited users belonged to. That's the whole vulnerability — an org-boundary scoping bug in an enterprise SSO flow — and it gave the attacker the keys to 138 customer accounts.

Six of those accounts got used to send phishing. Forty-three had contacts exfiltrated. The headline damage came from one campaign: a "Critical Security Alert: STM32 Entropy Vulnerability" email spoofing Trezor, sent from the real trezor@alerts.trezor.io through Brevo's real infrastructure, reaching 347,149 subscribers with roughly 2,500 clicks before Brevo shut it down. BitBox and CoinTracking got hit too. Brevo closed the hole within about two hours of detecting it, between 06:30 and 08:30 UTC on September 10.

Two hours of response time is fast. It doesn't matter, because the message passed SPF, DKIM, and DMARC cleanly — it came from Trezor's real Brevo account through Brevo's real sending infrastructure. This isn't spoofing. It's abuse of a legitimate mail stream, which is exactly the failure mode deliverability people have been warning marketers about for years and exactly the failure mode authentication doesn't stop. If you run enterprise SSO for a multi-tenant sending platform, audit your org-boundary scoping this week.

Sources: SecurityWeek, Malwarebytes, emailexpert

A Hacked Italian Government Mailbox Cost Revolut 680 Customers' Passport Scans

Attackers compromised a Prefecture of Reggio Calabria government mailbox on Italy's PEC certified-email system — which carries legal standing similar to registered mail — reportedly via infostealer malware. They then ran blockchain analysis to shortlist 680 high-value Revolut crypto accounts and submitted what looked like routine law-enforcement data requests. Revolut's compliance team processed them as legitimate and handed over passport scans, selfies, and crypto transaction histories.

A group calling itself "iamnotavillain" claims roughly 147GB of data and is demanding 6,000 Monero — about $3 million — to not release it.

The message authenticated cleanly. It came from a real government domain, over a system built specifically to carry legal weight. That's the entire lesson here: authentication tells you the message came from where it says it came from. It tells you nothing about whether the human who sent it should be trusted with your compliance team's cooperation. If you process legal or law-enforcement data requests over email, this is the week to review how those requests get verified before anyone acts on them.

Sources: SecurityAffairs, Irish Times, emailexpert

Microsoft Starts Throttling Exchange Servers That Skipped Last October's Patch

Exchange 2016 and 2019 servers that never applied the October 2025 security update are now getting throttled, then blocked, when routing mail to Exchange Online through on-prem inbound connectors. Watch your logs for error codes 4.7.230 and 5.7.230 — that's Microsoft telling you your server version, not your authentication, is the problem.

This is transport-level enforcement. A message can pass SPF, DKIM, and DMARC cleanly and still get rejected because the server that sent it is out of date. Pair it with the 60-day sending probation Microsoft rolled out for new Exchange Online tenants the same month (below), and the pattern is clear: Microsoft is tightening both the inbound and outbound trust boundaries around Exchange simultaneously. There's a second deadline buried in the same announcement worth flagging separately — EWS gets auto-disabled October 1, 2026 for any tenant that hasn't explicitly set EWSEnabled to True. If you're running on-prem Exchange talking to Exchange Online, patch now and check that EWS flag before the first of the month.

Source: emailexpert

82% of U.S. Campaign Domains Still Aren't Enforcing DMARC Ahead of the Midterms

DigiCert analyzed 3,756 U.S. political campaign domains. Eighty-two percent publish DMARC in monitor-only mode — p=none — which means the record exists but does nothing. Spoofed fundraising or voter-outreach email using a campaign's exact domain isn't blocked by mailbox providers; it just gets reported after the fact, if anyone's reading the reports at all.

It's a narrow claim — DMARC at p=none stops nothing, and even p=reject only stops exact-domain spoofing, not lookalikes — but it's the cleanest "enforcement vs. monitoring" stat we've seen all year, and election-season spoofing is a recurring seasonal problem. If you've ever needed one number to explain to a non-technical stakeholder why "we have a DMARC record" isn't the same as "we're protected," this is it.

Source: GlobeNewswire/DigiCert

Virgin Media Is Handing Millions of UK Mailboxes to Atmail — Expect List Decay by Halloween

Virgin Media O2 stopped issuing new addresses on ntlworld.com, blueyonder.co.uk, virgin.net, and virginmedia.com back in 2022, so every mailbox on those domains is at least four years old — exactly the kind of aged, engaged inbox senders build entire deliverability strategies around. Now those mailboxes are migrating to Junara, owned by Australian firm Atmail, rolling out in phases starting this month. Each user gets a 45-day decision window, then a 120-day recovery window before deletion.

Reputation doesn't carry over a mailbox migration. Expect the first attrition wave in late October — right into peak season — and a second wave roughly a year out when free transition pricing ends. If you have meaningful UK B2C lists, start flagging these four domains for engagement monitoring now, not when your bounce rate spikes in November.

Source: emailexpert

Deliverability & Authentication

SURBL Joins Validity in Blocklisting Cold-Outreach Domains — Up to the Parent Domain

Following up on last week's coverage of Validity's "Heatwave" public blocklist for synthetic domain warming: SURBL is now doing something arguably more aggressive. Steve and Laura at Word to the Wise report SURBL is actively listing domains involved in cold email outreach and escalating listings up to corporate parent domains — not just the throwaway subdomains senders were using to insulate their real brand.

Delisting denials are explicitly citing "warming services to fake domain reputation" and "obfuscating the identity of your primary domain." The author cites a client whose purchased list had a 12% hard-bounce rate, and reports "dozens of inquiries a week" from companies suddenly struggling with cold-email delivery. When two independent reputation services start pressuring the same list-selling and domain-warming ecosystem in the same month, that's not marketing from one vendor — that's the industry actually starting to feel it.

Source: Word to the Wise

Microsoft Puts New Exchange Online Tenants on 60-Day Sending Probation

New Exchange Online tenants now get graduated access to their own sending quota: 10% of the standard Tenant External Recipient Rate Limit under 31 days old, 25% at 31–60 days, full quota only past 60 days. Trial tenants get hit harder — their 24-hour external-recipient cap drops from 5,000 to 500, regardless of how many additional trial licenses you stack on.

This is aimed at disposable-tenant abuse — spin up, spam, burn, repeat. The catch: the TERRL applies org-wide, not per-mailbox, so it also throttles legitimate businesses standing up M365 for the first time. Rolled out starting September 14. If you're onboarding a new tenant this quarter, plan your first two months of sending volume around it.

Source: emailexpert

Infrastructure & MTAs

Salesforce's Dreamforce-Week Outage Exposed a Shared Failure Domain in Marketing Cloud Next

A September 16 outage — day two of Dreamforce, no less — took down an internal login service across hundreds of Salesforce instances in the US, Europe, India, and Japan for roughly 11.5 hours. Legacy Marketing Cloud Engagement, the old ExactTarget platform, kept sending because it sits on separate infrastructure. Marketing Cloud Next — the platform Salesforce is actively pushing customers toward — is built natively on Core and went down with everything else.

That's the trade-off nobody puts in the migration deck: the newer, more "integrated" platform bought its integration at the cost of an independent failure domain. If you're mid-migration to Marketing Cloud Next, or you rode out the outage on either platform, check for duplicate sends, volume spikes, and consent-data gaps from the window.

Source: emailexpert

Security & Anti-Abuse

Microsoft and CloudSEK: Attackers Are Renting Trust From Platforms You Already Whitelisted

A round-up worth reading in full, because it ties together three separate trust-abuse techniques active right now. First: ASCII-smuggling phishing relayed through ActiveCampaign using 148 finance-themed sender domains, peaking at 2.37 million messages on a weekday — Microsoft says Defender's non-keyword layers still catch about 99% of it, but that leaves 1% of 2.37 million landing somewhere. Second: browser-only credential harvesting using blob URLs and DocuSign-themed calendar invites that redirect through genuine Microsoft OAuth endpoints, using service workers for backend instructions so the attacker never needs to host a server at all. Third: "BigBear 2.0," an Evilginx2 phishing-as-a-service operation that CloudSEK compromised and exposed — 5,137 harvested credentials, 474 completed MFA bypasses, using custom JavaScript to force-downgrade victims off FIDO2.

Three different techniques, one common thread: none of them spoof anything. All three exploit authenticated, trusted infrastructure that recipients — and filters — already trust. That's the theme running through nearly every security story this week, from Brevo to Revolut to here. Authentication was never the finish line. It was table stakes, and the attackers moved on.

Source: emailexpert

Regulatory & Compliance

BBVA Italy Fined €5.5M Over a Broken Opt-Out Sync That Ran for Seven Months

A single customer complaint led Italy's Garante to fine BBVA's Italian branch €5.5 million — Decision No. 613, formalized September 3 — after the bank's in-app marketing opt-out never propagated to the CRM system actually sending the messages. The disconnect kept one customer receiving marketing for seven months, October 2025 through May 2026. The regulator cited GDPR Articles 5(1)(a), 12, and 21, and specifically called out BBVA for giving the customer inaccurate information about how its own systems worked when he complained.

The practical lesson for anyone running marketing off a CRM fed by a separate app or product database: opt-out sync latency and integrity is now a compliance surface, not a UX nuisance you fix whenever engineering gets around to it. Check your opt-out propagation path before your regulator does.

Sources: MLex, DataGuidance

Events & Community


Links worth your time:

That's the week. If something is wrong, reply and tell me — I read every response.

— John


This Week In Email — thisweekin.email

Enjoyed this issue?

Subscribe to This Week in Email and get future issues delivered to your inbox.