Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

A flaw in email service Brevo’s login system let an attacker access 138 client accounts, enabling phishing messages to be sent to subscribers of multiple crypto firms. The incident resulted in a fraudulent email being delivered to about 347,000 Trezor newsletter recipients and similar messages distributed via BitBox and CoinTracking accounts.

By AI NewsroomPublished about 1 hour agoUpdated about 1 hour ago0 views
Brevo login flaw enabled phishing email targeting 347K Trezor subscribers

Why It Matters

The breach shows how a single platform-level authorization error can let attackers reach large, vetted subscriber lists and bypass normal email authentication, increasing the risk that recipients will treat malicious communications as legitimate.

Key Facts

  • Brevo accounts accessed: 138 client accounts
  • Trezor subscribers messaged: Approximately 347,000
  • Clicks on malicious link: About 2,500 users accessed the linked app before takedown
  • Accounts used to send phishing: Six accounts
  • Accounts with contacts exported: 43 accounts

Brevo said an attacker abused a weakness in its login flow to gain control of 138 client accounts, which allowed fraudulent emails to be sent from multiple customers’ accounts. In a postmortem, the email provider explained the attacker created a Brevo account, enabled single sign-on (SSO) and invited legitimate users into that setup; a failure in the authorization boundary then let the intruder reach every organization accessible to the invited users.

The company reported that six compromised accounts were used to send phishing emails, contacts were exported from 43 accounts, and 93 accounts showed no meaningful activity, although Brevo did not clarify whether those groups overlap. Because the malicious messages originated from customers’ Brevo accounts, some of them passed normal authentication checks and looked authentic to recipients.

Hardware wallet maker Trezor said the phishing message, headlined “Critical Security Alert: STM32 Entropy Vulnerability,” linked to an app that asked users to submit wallet backups. Trezor disabled the domain at the DNS level within about 20 minutes, but roughly 2,500 people visited the link before it was taken down. A company spokesperson told Cointelegraph the initial email was sent to about 347,000 customers, and that Brevo’s account held only opt-in newsletter addresses; Trezor is treating those addresses as potentially known to the attacker until it receives more information from Brevo.

BitBox reported a similar unauthorized email went out via Brevo to its full newsletter and tutorial list; the firm said Brevo stored only email addresses and language preferences and that it has found no evidence of leaked credentials, downloaded contacts, lost funds or disclosed recovery phrases so far. CoinTracking said its Brevo account distributed a message titled “Data Breach Notice: Please refresh API Keys as soon as possible” and warned recipients not to click the links. Cointelegraph contacted Brevo for comment but had not received a response before publication.

Keep Reading