Brevo login flaw enabled phishing email targeting 347K Trezor subscribers
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
An attacker exploited a login flaw in the email platform Brevo to access 138 client accounts and send phishing emails to around 347,000 Trezor subscribers. The attacker also distributed fraudulent messages via accounts linked to hardware wallet maker BitBox and crypto portfolio platform CoinTracking. Brevo acknowledged the breach involved authorization errors that allowed broader access than intended.
Why it matters
This phishing attack targeted large subscriber bases of prominent crypto companies, potentially putting users at risk of exposing wallet backups and other sensitive information. The emails passed usual authentication checks, increasing the likelihood users trusted them. The source does not elaborate on wider market or regulatory impacts.
Key context
The attacker created a Brevo account, used single sign-on, and invited legitimate users, leading to unauthorized access across organizations due to an authorization boundary failure. Trezor quickly disabled the malicious domain after about 2,500 clicks on the phishing link. BitBox and CoinTracking confirmed limited data exposure but are awaiting more detailed logs from Brevo.
Key numbers and entities
Brevo, Trezor, BitBox, CoinTracking; 138 client accounts accessed; approximately 347,000 Trezor newsletter recipients targeted; some 2,500 users clicked the phishing link before takedown.
What remains unclear
The source does not provide details on whether the account categories of activity overlapped, the full extent of data accessed beyond email addresses, or Brevo’s response plans beyond acknowledging the flaw. It is also unknown whether any user funds or recovery phrases were compromised.