Brevo Login Flaw Exposes 138 Client Accounts in Trezor Phishing Attack
A security flaw in email marketing platform Brevo allowed an attacker to access 138 client accounts, with one compromised account belonging to hardware wallet maker Trezor being used to distribute a phishing campaign to its subscribers, according to CoinMarketCap.
Brevo later disclosed that the attacker exploited a flaw involving its SAML single sign-on system. Of the 138 accounts accessed, six were used to send phishing emails, contacts were exported from 43 accounts, while 93 accounts showed no meaningful activity.
Trezor Subscribers Targeted Through Compromised Email Infrastructure
Trezor said the incident affected roughly 347,000 email addresses in its opt-in newsletter database. The phishing message was designed to appear as a security alert and contained a malicious link leading users toward an application that requested their wallet backup. Trezor emphasized that its own wallet, product and account systems were not compromised.
The company said it took down the malicious domain at the DNS level within 20 minutes. By that point, about 2,500 people had clicked the link. Trezor has advised recipients not to interact with suspicious messages and said anyone who entered a wallet backup should immediately move funds to a new wallet.
The incident also highlights the security risks created by third-party service providers. Other cryptocurrency companies, including BitBox and CoinTracking, were also targeted through Brevo accounts, indicating that the compromise extended beyond a single crypto company.
Brevo Breach Raises Supply-Chain Security Concerns
The attack demonstrates how compromising an markets infrastructure provider can give attackers access to trusted communication channels without directly breaching the underlying systems of each affected company. Because legitimate email infrastructure was involved, phishing messages could appear more credible to recipients and potentially bypass some conventional defenses.
For crypto companies, the incident reinforces the importance of securing vendors that handle customer communications, mailing databases and authentication infrastructure. Trezor said it has suspended its Brevo account and is reviewing its vendor relationships and security requirements following the incident.
The immediate priority remains protecting affected newsletter recipients from follow-up phishing attempts. Trezor said it is treating the roughly 347,000 newsletter addresses as potentially known to the attacker, making continued vigilance necessary even after the original malicious domain was disabled.
Writer: Victoria HaleTechnology & Blockchain WriterVictoria Hale writes about blockchain technology, digital infrastructure, and the intersection of emerging technologies with finance. Her articles explore how new protocols and systems are shaping the evolving digital economy.She prioritises clarity and accuracy when explaining technical developments to a general audience.
Check out other news and articles on Google News
Disclaimer:
The articles on HOKA.NEWS are here to keep you updated on the latest buzz in crypto, tech, and beyond—but they’re not financial advice. We’re sharing info, trends, and insights, not telling you to buy, sell, or invest. Always do your own homework before making any money moves.
HOKA.NEWS isn’t responsible for any losses, gains, or chaos that might happen if you act on what you read here. Investment decisions should come from your own research—and, ideally, guidance from a qualified financial advisor. Remember: crypto and tech move fast, info changes in a blink, and while we aim for accuracy, we can’t promise it’s 100% complete or up-to-date.