An authentication weakness in the Brevo email marketing service enabled a malicious actor to compromise 138 customer accounts and distribute phishing messages to hundreds of thousands of cryptocurrency holders.
The security incident impacted Trezor, BitBox, and CoinTracking, which all relied on Brevo’s platform for managing their email subscriber databases.
The threat actor established a Brevo account, activated single sign-on functionality, and sent invitations to genuine Brevo users to join the configuration. A critical authorization boundary weakness subsequently provided the attacker with access to all organizations those invited users had permissions for.
Brevo’s subsequent investigation revealed that six compromised accounts were utilized to distribute phishing communications, 43 accounts had contact lists extracted, and 93 accounts displayed no significant unauthorized activity.
The campaign was engineered to circumvent standard email verification protocols, causing the fraudulent messages to appear legitimate to those who received them.
Trezor’s database of 347,000 newsletter recipients was sent an email with the heading “Critical Security Alert: STM32 Entropy Vulnerability.”
The message included a hyperlink directing users to a counterfeit application designed to capture wallet recovery phrases, providing attackers complete control over victim funds.
Trezor deactivated the fraudulent domain through DNS-level intervention within 20 minutes of identifying the unauthorized email. Approximately 2,500 recipients had already accessed the link during that window.
Trezor has verified that its Brevo account contained exclusively opt-in newsletter email addresses. No login credentials, wallet information, or additional personal data was maintained on the platform.
The organization is now considering all 347,000 addresses as potentially compromised and vulnerable to subsequent phishing campaigns.
BitBox reported that the fraudulent email was delivered to its complete newsletter and educational content subscriber base via Brevo. The company’s investigation found no indication of extracted contact databases, compromised funds, or exposed seed phrases.
BitBox verified that its Brevo account stored exclusively email addresses and user language preference settings.
CoinTracking’s Brevo infrastructure was exploited to distribute a message with the subject line “Data Breach Notice: Please refresh API Keys as soon as possible.” The organization cautioned subscribers against interacting with any hyperlinks contained in that communication.
Trezor has deactivated its Brevo account and implemented alert notifications throughout its website, mobile application, and customer support platforms.
If you provided your wallet recovery phrase after accessing the fraudulent link, Trezor recommends transferring assets to a newly generated wallet without delay. Simply clicking the link without submitting information does not compromise your cryptocurrency holdings.
Trezor has announced it is conducting a comprehensive evaluation of its third-party service providers and security protocols in response to this incident.
The post Brevo Security Breach Exposes 347,000 Trezor Users to Phishing Attack appeared first on Blockonomi.