
AI-generated summary
Paymium is a French cryptocurrency exchange platform subject to KYC obligations. Brevo is an e-mail service provider used for sending communications. An SSO flaw at Brevo allowed an intrusion on September 10, exploiting single sign-on to access customer data.
New collateral victim. After the fake emails from Trezor, it is the turn of Paymium customers to discover that their identity card may have slipped through the back room. The French platform warned its users on September 22. Its e-mail service provider Brevo had already served as a launching pad for the phishing campaign against Trezor, BitBox and CoinTracking in early September. No funds have moved. But a file of identified crypto holders is worth its weight in gold in the midst of a wave of kidnappings.
Key Points
Paymium warned its customers on September 22 of unauthorized access to its email router
Identity, date of birth, telephone number and country of residence appear in the lot
No password, no API key, no access to funds depending on the platform
At Brevo, 138 customer accounts were opened thanks to a single connection flaw
Paymium data leak, bill arrives twelve days later
The message arrives in inboxes twelve days after the fact. Paymium explains that Brevo, the tool which manages part of its shipments, has suffered an intrusion. According to the notification relayed by FrenchBreaches, the intruder was able to consult the email address, account identifier, last name, first name, date of birth, telephone number and country of residence of the customers concerned. How many are there? The platform does not say this.
On the reassuring side, the list of what has not leaked is long. No password, no API key, no wallet data or tax information passed through Brevo, assures Paymium. No fraudulent emails would have left his account either.
Brevo, an SSO fault as big as a carriage entrance
It all starts with an acronym, SSO (single authentication which allows you to connect to several services with a single identifier). The incident report released by Brevo describes an almost vexing scenario. The attacker opens his own account, plugs in an identity provider he controls, then invites legitimate users. It then logs in for them. And the access thus obtained, poorly partitioned, was not limited to one organization but extended to all those that these users could reach.
Spotted on September 10 at 6:30 a.m. (UTC), the breach was sealed two hours later. Out of 138 customer accounts visited, 43 had their contact lists exported and six were used to send phishing messages. Paymium doesn't say which group it falls into.
It was from one of these six accounts that nearly 347,000 Trezor subscribers received a false security alert, with around 2,500 clicks involved.
Leak from Paymium, a file that makes scammers salivate
Regulated platforms must verify the identity of their customers (the famous KYC). They also have to write to them, and often entrust this chore to a subcontractor. Your date of birth and your mobile number therefore lie dormant with a third party that you never chose. The cocktail has everything to please a crook. He knows that you hold cryptos, what country you live in, what to call you and how old you are, enough to set up a false call from the “Paymium security service” that is unmistakably credible.
The previous Ledger has lost none of its relevance. In December 2020, the postal details of more than 270,000 of the manufacturer's customers landed on a hacker forum, followed by a barrage of threats. No postal address here. But the France of 2026 is no longer a theoretical terrain for the physical targeting of crypto holders.
Paymium customers, the reflexes to adopt after the leak
Paymium refers its customers to cybermalveillance.gouv.fr, the free public assistance system. Add a few reflexes that cost nothing.
Do not click on any link received by email or SMS on behalf of Paymium, go through the application or type the address yourself
An “advisor” who calls you to secure your account is an imposter, hang up
Never communicate your recovery phrase to anyone
Enable two-factor authentication if you haven't already
AI outlook — possibilities, not facts
Paymium will strengthen its controls on KYC data handling providers
Likely · Within weeks
Brevo will notify its business customers of the incident and offer an SSO security audit
Very likely · Within days

The Services and Payment Agency confirms a data leak via fraudulent access to a user account on August 27, 2026, detected the next day. More than 143,000 people would be affected according to FrenchBreaches, with 2023-2024 payment notices from the Île-de-France “Coup de Pouce Energie” system containing names, addresses, IBAN/BIC, beneficiary numbers and amounts paid. This is the second such leak at ASP in five months.

China opened an investigation in late September 2026 into DeepSeek and Moonshot AI after Anthropic's accusations of allegedly using fraudulent accounts to train their models on Claude's responses. CAC investigators are seeking to determine whether sensitive Chinese data was transferred to U.S. servers, rather than focusing on alleged technological theft to the detriment of Anthropic.

Ukraine's Ministry of Digital Transformation gains access to Daybreak, OpenAI's cybersecurity tool powered by GPT-5.6 Sol, to audit its aging infrastructure in the face of Russian attacks.

Cardano joins the x402 protocol, enabling automated payments for AI agents and online services. The official TypeScript kit now supports ADA and native tokens, although usage is currently limited to the staging network.

More than 52 bitcoins from the Coldcard wallet hack were transferred to a legal trust in Wyoming to be returned to their owners, after being sheltered by ethical hackers.

Anthropic unveiled Claude Opus 5.5, sold 40% cheaper, followed immediately by OpenAI and its new GPT-6 Sol and Luna models at knockdown prices. This price war comes as Anthropic's IPO on Nasdaq approaches.