Critical Brevo Security Flaw Exposes 347K Trezor Subscribers to Phishing Attack

Brevo’s login flaw exposed 347K Trezor subscribers to phishing, while BitBox and CoinTracking also assess potential email-list exposure.
Table of Contents

TL;DR:

  • Brevo’s login flaw exposed 138 client accounts and enabled phishing emails to reach about 347,000 Trezor newsletter subscribers, plus BitBox and CoinTracking users.
  • Trezor disabled the malicious domain within 20 minutes, but around 2,500 people had already opened a fake security alert requesting wallet backups.
  • Trezor is treating all 347,000 newsletter addresses as potentially reusable for phishing, while BitBox and CoinTracking continue assessing exposure and warning users in the incident.

A login flaw in Brevo’s email platform enabled an attacker to access 138 client accounts, opening the door to phishing campaigns that reached cryptocurrency users through trusted company mailing systems. Trezor said approximately 347,000 newsletter subscribers received a fraudulent message, while BitBox and CoinTracking were also affected through their Brevo accounts. The breach was especially dangerous because the phishing emails passed normal authentication checks and appeared legitimate to recipients. Brevo said six compromised accounts were used to send phishing messages, contacts were exported from 43 accounts, and 93 accounts showed no meaningful activity overall today.

The attack began when the threat actor created a Brevo account, enabled single sign-on, and invited Brevo users into it. Access should have remained limited to the attacker’s organization, but an authorization-boundary failure exposed every organization the invited users could reach. A flaw in account permissions effectively turned trusted user access into a bridge across multiple customer environments. Trezor’s phishing email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” directed recipients to an app that requested wallet backups. Trezor disabled the malicious domain within 20 minutes, though about 2,500 people had already opened the link initially.

Brevo’s login flaw exposed 138 client accounts and enabled phishing

Crypto Firms Assess Exposure After Brevo Login Failure

Trezor said its Brevo account contained only opt-in newsletter email addresses and no other customer data, yet it is treating all 347,000 addresses as known to the attacker and potentially reusable for future phishing. The immediate breach may have ended, but the exposed mailing list creates an ongoing social-engineering risk. BitBox said its unauthorized message appeared to reach its full newsletter and tutorial list. The company found no evidence that credentials were compromised, contacts downloaded, funds lost, or recovery phrases disclosed, but it is still treating the list as potentially accessed while awaiting logs now.

CoinTracking reported that its Brevo account distributed a fraudulent email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” and warned users not to follow links inside it. The incident shows how a provider-side authentication weakness can spread phishing risk across several crypto services without compromising their core systems. For Trezor users, the most serious element remains the wallet-backup request embedded in the fake alert, because recovery information can give attackers control over funds. With Brevo’s investigation continuing, affected companies are focused on limiting phishing attempts against addresses that may remain exposed.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews