Swap Crypto into SHM With Houdini

Notice Regarding Unauthorized Phishing Email

Notice Regarding Unauthorized Phishing Email

We identified unauthorized phishing emails sent through Shardeum’s account with Brevo, our third-party email service provider. These messages were not sent or approved by Shardeum. This email...

Back to top

We identified unauthorized phishing emails sent through Shardeum’s account with Brevo, our third-party email service provider. These messages were not sent or approved by Shardeum.

This email incident is unrelated to the Shardeum network and has no impact on its operation.

What Happened

We identified the incident on September 21, 2026, and began securing the account and investigating with Brevo. Brevo subsequently confirmed that compromised API credentials were used to send unauthorized emails, with the main sending activity occurring on September 17–18.

The messages used a Shardeum sender address while impersonating services such as Prime Video and presenting subscription-renewal or healthcare-related notices. These messages were not approved by Shardeum.

Brevo reports that the affected credentials have been revoked and unauthorized sending has stopped, after temporarily suspending email sending as a protective measure.

Who May Have Received These Emails

The unauthorized messages almost entirely targeted addresses added or supplied by the attacker, rather than Shardeum’s existing subscriber list. Our review of the available sending logs identified 10 pre-existing subscriber email addresses among the targeted recipients; the remaining addresses did not match our existing subscriber list.

Brevo found no contact-export activity during the incident window.

What We Have Done

We have taken steps to secure the email account, including revoking existing credentials, changing the password, and strengthening access controls.

What You Should Do

If you received an unexpected renewal, payment, or healthcare-related email using a Shardeum sender address:

  • Do not click its links, open attachments, or reply.
  • Do not share passwords, verification codes, seed phrases, or payment information.
  • Report the message as phishing through your email provider and delete it.
  • If you entered a password, change it through the relevant service’s official website or app.
  • If you provided payment details, contact your bank or card issuer promptly.

You do not need to take any action on the Shardeum network because of this email incident.

For Questions

If you have questions or need assistance, please contact our team @ [email protected]

0
The Shard

Sign up for The Shard community newsletter

Stay updated on major developments about Shardeum.