A trusted ESP got its SSO scoping wrong and 347,000 Trezor subscribers paid for it. A hacked Italian government mailbox talked Revolut into handing over passport scans on 680 crypto whales. Microsoft is squeezing both ends of the Exchange pipe at once. And 82% of U.S. campaign domains are still sitting on p=none seven weeks out from the midterms.
It's a heavy one, and the through-line is ugly: almost every major security story this week involves fully authenticated, legitimately-sent mail. SPF passed. DKIM passed. DMARC passed. The attackers didn't spoof anything — they got inside infrastructure senders and recipients already trusted and rode it. Let's get into it.
An attacker created their own Brevo organization, turned on SSO, and invited legitimate users into it. Because access wasn't scoped to the org SSO was actually configured for, those invited accounts could reach every other org the invited users belonged to. That's the whole vulnerability — an org-boundary scoping bug in an enterprise SSO flow — and it gave the attacker the keys to 138 customer accounts.
Six of those accounts got used to send phishing. Forty-three had contacts exfiltrated. The headline damage came from one campaign: a "Critical Security Alert: STM32 Entropy Vulnerability" email spoofing Trezor, sent from the real trezor@alerts.trezor.io through Brevo's real infrastructure, reaching 347,149 subscribers with roughly 2,500 clicks before Brevo shut it down. BitBox and CoinTracking got hit too. Brevo closed the hole within about two hours of detecting it, between 06:30 and 08:30 UTC on September 10.
Two hours of response time is fast. It doesn't matter, because the message passed SPF, DKIM, and DMARC cleanly — it came from Trezor's real Brevo account through Brevo's real sending infrastructure. This isn't spoofing. It's abuse of a legitimate mail stream, which is exactly the failure mode deliverability people have been warning marketers about for years and exactly the failure mode authentication doesn't stop. If you run enterprise SSO for a multi-tenant sending platform, audit your org-boundary scoping this week.
Sources: SecurityWeek, Malwarebytes, emailexpert
Sponsored

Your email list doesn't stay clean just because you stopped touching it.
People change jobs. Inboxes get abandoned. Domains expire. Temporary addresses disappear. And that perfectly healthy email you collected six months ago? It might be a bounce waiting to happen today.
That's why list cleaning shouldn't start only when your bounce rate starts looking scary.
Before an important campaign, running your list through email verification helps you understand what's actually sitting in your database, which addresses are safe to send to, which need a little more caution, and which are better left out of the send altogether.
That's where Bouncer comes in.
Bouncer verifies your email lists and helps identify invalid, risky, disposable, and other problematic addresses before they reach your campaigns. You get clear results that make it easier to decide who to send to without throwing away good contacts unnecessarily.
And because cleaner sending isn't just about avoiding a few bounces. High bounce rates can hurt your sender reputation and, eventually, your ability to reach the inbox at all.
With Bouncer, you can clean a list before a big campaign, verify emails as they enter your database, or connect verification directly to the tools you already use.
Less guessing. Fewer avoidable bounces. A healthier list before you hit Send.
Clean your list with Bouncer →Attackers compromised a Prefecture of Reggio Calabria government mailbox on Italy's PEC certified-email system — which carries legal standing similar to registered mail — reportedly via infostealer malware. They then ran blockchain analysis to shortlist 680 high-value Revolut crypto accounts and submitted what looked like routine law-enforcement data requests. Revolut's compliance team processed them as legitimate and handed over passport scans, selfies, and crypto transaction histories.
A group calling itself "iamnotavillain" claims roughly 147GB of data and is demanding 6,000 Monero — about $3 million — to not release it.
The message authenticated cleanly. It came from a real government domain, over a system built specifically to carry legal weight. That's the entire lesson here: authentication tells you the message came from where it says it came from. It tells you nothing about whether the human who sent it should be trusted with your compliance team's cooperation. If you process legal or law-enforcement data requests over email, this is the week to review how those requests get verified before anyone acts on them.
Sources: SecurityAffairs, Irish Times, emailexpert
Exchange 2016 and 2019 servers that never applied the October 2025 security update are now getting throttled, then blocked, when routing mail to Exchange Online through on-prem inbound connectors. Watch your logs for error codes 4.7.230 and 5.7.230 — that's Microsoft telling you your server version, not your authentication, is the problem.
This is transport-level enforcement. A message can pass SPF, DKIM, and DMARC cleanly and still get rejected because the server that sent it is out of date. Pair it with the 60-day sending probation Microsoft rolled out for new Exchange Online tenants the same month (below), and the pattern is clear: Microsoft is tightening both the inbound and outbound trust boundaries around Exchange simultaneously. There's a second deadline buried in the same announcement worth flagging separately — EWS gets auto-disabled October 1, 2026 for any tenant that hasn't explicitly set EWSEnabled to True. If you're running on-prem Exchange talking to Exchange Online, patch now and check that EWS flag before the first of the month.
Source: emailexpert
DigiCert analyzed 3,756 U.S. political campaign domains. Eighty-two percent publish DMARC in monitor-only mode — p=none — which means the record exists but does nothing. Spoofed fundraising or voter-outreach email using a campaign's exact domain isn't blocked by mailbox providers; it just gets reported after the fact, if anyone's reading the reports at all.
It's a narrow claim — DMARC at p=none stops nothing, and even p=reject only stops exact-domain spoofing, not lookalikes — but it's the cleanest "enforcement vs. monitoring" stat we've seen all year, and election-season spoofing is a recurring seasonal problem. If you've ever needed one number to explain to a non-technical stakeholder why "we have a DMARC record" isn't the same as "we're protected," this is it.
Source: GlobeNewswire/DigiCert
Virgin Media O2 stopped issuing new addresses on ntlworld.com, blueyonder.co.uk, virgin.net, and virginmedia.com back in 2022, so every mailbox on those domains is at least four years old — exactly the kind of aged, engaged inbox senders build entire deliverability strategies around. Now those mailboxes are migrating to Junara, owned by Australian firm Atmail, rolling out in phases starting this month. Each user gets a 45-day decision window, then a 120-day recovery window before deletion.
Reputation doesn't carry over a mailbox migration. Expect the first attrition wave in late October — right into peak season — and a second wave roughly a year out when free transition pricing ends. If you have meaningful UK B2C lists, start flagging these four domains for engagement monitoring now, not when your bounce rate spikes in November.
Source: emailexpert
Following up on last week's coverage of Validity's "Heatwave" public blocklist for synthetic domain warming: SURBL is now doing something arguably more aggressive. Steve and Laura at Word to the Wise report SURBL is actively listing domains involved in cold email outreach and escalating listings up to corporate parent domains — not just the throwaway subdomains senders were using to insulate their real brand.
Delisting denials are explicitly citing "warming services to fake domain reputation" and "obfuscating the identity of your primary domain." The author cites a client whose purchased list had a 12% hard-bounce rate, and reports "dozens of inquiries a week" from companies suddenly struggling with cold-email delivery. When two independent reputation services start pressuring the same list-selling and domain-warming ecosystem in the same month, that's not marketing from one vendor — that's the industry actually starting to feel it.
Source: Word to the Wise
New Exchange Online tenants now get graduated access to their own sending quota: 10% of the standard Tenant External Recipient Rate Limit under 31 days old, 25% at 31–60 days, full quota only past 60 days. Trial tenants get hit harder — their 24-hour external-recipient cap drops from 5,000 to 500, regardless of how many additional trial licenses you stack on.
This is aimed at disposable-tenant abuse — spin up, spam, burn, repeat. The catch: the TERRL applies org-wide, not per-mailbox, so it also throttles legitimate businesses standing up M365 for the first time. Rolled out starting September 14. If you're onboarding a new tenant this quarter, plan your first two months of sending volume around it.
Source: emailexpert
A September 16 outage — day two of Dreamforce, no less — took down an internal login service across hundreds of Salesforce instances in the US, Europe, India, and Japan for roughly 11.5 hours. Legacy Marketing Cloud Engagement, the old ExactTarget platform, kept sending because it sits on separate infrastructure. Marketing Cloud Next — the platform Salesforce is actively pushing customers toward — is built natively on Core and went down with everything else.
That's the trade-off nobody puts in the migration deck: the newer, more "integrated" platform bought its integration at the cost of an independent failure domain. If you're mid-migration to Marketing Cloud Next, or you rode out the outage on either platform, check for duplicate sends, volume spikes, and consent-data gaps from the window.
Source: emailexpert
A round-up worth reading in full, because it ties together three separate trust-abuse techniques active right now. First: ASCII-smuggling phishing relayed through ActiveCampaign using 148 finance-themed sender domains, peaking at 2.37 million messages on a weekday — Microsoft says Defender's non-keyword layers still catch about 99% of it, but that leaves 1% of 2.37 million landing somewhere. Second: browser-only credential harvesting using blob URLs and DocuSign-themed calendar invites that redirect through genuine Microsoft OAuth endpoints, using service workers for backend instructions so the attacker never needs to host a server at all. Third: "BigBear 2.0," an Evilginx2 phishing-as-a-service operation that CloudSEK compromised and exposed — 5,137 harvested credentials, 474 completed MFA bypasses, using custom JavaScript to force-downgrade victims off FIDO2.
Three different techniques, one common thread: none of them spoof anything. All three exploit authenticated, trusted infrastructure that recipients — and filters — already trust. That's the theme running through nearly every security story this week, from Brevo to Revolut to here. Authentication was never the finish line. It was table stakes, and the attackers moved on.
Source: emailexpert
A single customer complaint led Italy's Garante to fine BBVA's Italian branch €5.5 million — Decision No. 613, formalized September 3 — after the bank's in-app marketing opt-out never propagated to the CRM system actually sending the messages. The disconnect kept one customer receiving marketing for seven months, October 2025 through May 2026. The regulator cited GDPR Articles 5(1)(a), 12, and 21, and specifically called out BBVA for giving the customer inaccurate information about how its own systems worked when he complained.
The practical lesson for anyone running marketing off a CRM fed by a separate app or product database: opt-out sync latency and integrity is now a compliance surface, not a UX nuisance you fix whenever engineering gets around to it. Check your opt-out propagation path before your regulator does.
Sources: MLex, DataGuidance
Links worth your time:
That's the week. If something is wrong, reply and tell me — I read every response.
— John
This Week In Email — thisweekin.email
Subscribe to This Week in Email and get future issues delivered to your inbox.