Incident report for August 5, 2026
A summary of what happened, what we know, and what we are doing next.
Summary
On August 1, 2026, Sendblue received reports that some contacts had received fraudulent SMS messages impersonating Sendblue customers and requesting payment through a suspicious link.
The fraudulent messages were not sent through Sendblue. They were sent from external Sinch toll-free numbers and directed recipients to a domain that is not owned or operated by Sendblue.
We are treating this as a security incident because the campaign targeted phone numbers associated with Sendblue customer messaging activity.
On July 31, 2026, an external security researcher reported a vulnerability in our Firebase/Firestore security rules. We immediately treated the issue as a SEV-0 incident and fixed the vulnerability that day.
Our investigation has identified unauthorized access to certain Firebase/Firestore conversation records on July 7 and July 10. Based on the evidence reviewed to date, the information involved may include message content, phone numbers, contact information, Sendblue line associations, Sendblue organization user names, and related messaging metadata.
For some customers, we have confirmed that records were accessed. Other customers had records that were accessible through the affected paths, but we have not confirmed that those records were retrieved. We are contacting affected customers directly and providing information specific to their accounts.
Our investigation remains active. We have preserved relevant evidence, engaged Oneleet, our third-party cybersecurity partner, and have begun reporting the incident to the relevant authorities. We are continuing to assess the full scope of the incident and will update this notice if our findings materially change.
How this affects you
No technical action is required to continue using the Sendblue service at this time.
If one of your contacts received a fraudulent message, they should not click the link, submit payment, or provide personal or financial information.
The known scam domain, shown in defanged form, is:
pay[.]246114[.]xyzThe known external sender numbers are:
- +1 833 751 7935
- +1 888 751 7935
A representative message looked like this:
[Business Name]: Your onboarding call deposit ($49.00) is due.
Pay securely: hxxp://pay[.]246114[.]xyz/...Customers who receive a direct notice from Sendblue should follow the instructions in that notice. Those notices will reflect the information currently known about each customer's affected records.
Actions and remediations
- Fixed the Firebase/Firestore security-rules vulnerability.
- Preserved relevant records, logs, indicators, and customer reports.
- Engaged Oneleet to support the investigation and review our remediation.
- Begun notifying customers whose information was accessed or may have been exposed.
- We have begun the process of reporting the incident to relevant U.S. and European authorities.
- Contacted Sinch regarding the external sender numbers. Sinch has confirmed that the numbers were taken out of service.
- Submitted the fraudulent payment domain for takedown. AWS has confirmed that the payment links were removed.
Ongoing work
- Validating the affected-data analysis for each customer.
- Reviewing whether any additional data or systems were involved.
- Monitoring for further fraudulent activity.
- Expanding alerts for unusual access patterns.
- Reviewing and strengthening access controls across our backend systems.
- Providing affected customers with material updates as the investigation develops.
Contact
We sincerely apologize to everyone affected by this incident.
Our customers trust Sendblue with important communications. We take that responsibility seriously. We will continue the investigation, communicate directly with affected customers, and publish material updates as our findings develop.
Please contact security@sendblue.com with questions or additional examples of fraudulent messages.
You might also find it interesting
Don't leave us on read
Drive sales with the most engaging messaging channel.
