Marthio Marthio
Crypto

Brevo security flaw enabled phishing attack on 347,000 Trezor subscribers

A login flaw in Brevo exposed roughly 347,000 crypto subscribers to phishing emails. Multiple hardware wallet and tax platforms confirmed the breach.

An attacker exploited a login system vulnerability in the email platform Brevo to compromise approximately 138 client accounts. This breach allowed the distribution of phishing emails targeting roughly 347,000 newsletter subscribers from hardware wallet maker Trezor and platforms BitBox and CoinTracking. In its Thursday postmortem, Brevo stated that six specific accounts were utilized to send fraudulent messages, while contacts exported from 43 and 93 other accounts showed no meaningful activity during the incident. The company explained that the attacker created a new account, enabled single sign-on, and invited legitimate users into the configuration. This action caused an authorization boundary failure, granting access to every organization those users could reach. The platform did not confirm whether these three categories of accounts overlapped. Earlier this week, Trezor and BitBox had warned their communities about the threat. In a recent blog post, Trezor confirmed the phishing message contained a link requesting wallet backups. The firm disabled the relevant domain at the DNS level within 20 minutes but noted that some users had already clicked the malicious link.

TrezorCybersecurity breachEmail platformPhishing attackBrevoHardware walletBitboxCointrackingSubscriber exposureDigital security risk