Skip to main content

Brevo Login Flaw Used to Phish 347K Trezor Users



A flaw in Brevo’s email login setup allowed an attacker to access client accounts and launch phishing campaigns that targeted subscribers of multiple crypto companies, including Trezor. Brevo’s post-incident write-up says 138 client accounts were involved, with phishing messages sent through infrastructure connected to hardware wallet maker BitBox and crypto portfolio tracking and tax-reporting platform CoinTracking.



The incident matters for users because it highlights how widely used marketing and notification providers can become a bridge for account-based compromise—one that can bypass typical email authentication safeguards and reach audiences that expect legitimate updates.



Key takeaways



  • Brevo said an attacker used a login-system issue to gain access to 138 client accounts and send phishing emails from six of them.

  • Trezor reported that the initial phishing email was sent to roughly 347,000 newsletter customers, and it disabled the malicious domain within about 20 minutes.

  • Trezor, BitBox, and CoinTracking share the same email provider for newsletters, which enabled the attacker to pivot across multiple crypto audiences.

  • Brevo said an intended authorization boundary failed, allowing access beyond the organization where invited Brevo users belonged.

  • Crypto firms are treating their affected newsletter lists as potentially exposed and possibly reusable for further phishing attempts until more details emerge.



Brevo’s incident report: authorization boundary failure


In a Thursday postmortem, Brevo described how the attacker exploited a vulnerability in its login system to reach other organizations. Brevo said six accounts were used to send phishing emails. It also reported that contacts were exported from 43 accounts, while 93 accounts showed no meaningful activity. The company did not clarify whether those categories overlapped.



According to Brevo’s write-up, the attacker created a Brevo account, enabled single sign-on, and invited legitimate Brevo users into the configuration. Brevo said access should have been confined to a single organization, but the authorization boundary failed—granting the attacker access to every organization the invited users could reach.



Brevo also published its incident details through its status page, including the write-up referenced by affected companies.



Why crypto newsletters looked legitimate


The scope of the phishing effort expanded on earlier warnings from Trezor and BitBox, which had flagged that their shared email provider could be used to deliver convincing messages. Earlier coverage from Cointelegraph noted how the attack was able to pass normal authentication checks and appear genuine to recipients.



That combination—credible branding plus delivery through a familiar provider—makes these campaigns especially dangerous. Users are more likely to trust emails that match the expected tone and format of official newsletters, even when the link or call-to-action is malicious.



Trezor: app request tied to wallet backups


In a separate blog post, Trezor detailed what it said the phishing message contained. The email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” included a link to an app that asked users for their wallet backups.



Trezor said it disabled the domain at the DNS level within 20 minutes. Even so, it reported that roughly 2,500 people accessed the link before the takedown.



A Trezor spokesperson told Cointelegraph that the initial email was sent to 347,000 customers and that all of those newsletter subscribers were later contacted about the risk. The company said its Brevo account stored only opt-in newsletter email addresses and no other customer data.



Until additional information is provided by Brevo, the spokesperson added that Trezor is treating the roughly 347,000 newsletter addresses as known to the attacker and possibly reusable for future phishing.



BitBox and CoinTracking: lists potentially exposed


BitBox said its unauthorized email was sent through Brevo and appeared to reach its full newsletter and tutorial list. In comments relayed to Cointelegraph, a BitBox spokesperson said the Brevo account stored only email addresses and language preferences.



BitBox reported that it found no evidence of compromised company credentials, did not observe downloads of contacts beyond what would be expected in normal operations, and saw no signs of lost funds or disclosure of recovery phrases. However, it said it is treating the newsletter list as potentially accessed while it awaits Brevo’s logs.



CoinTracking, meanwhile, said its Brevo account distributed an email titled “Data Breach Notice: Please refresh API Keys as soon as possible.” CoinTracking told recipients not to follow the email’s links.



Taken together, these responses underscore a common pattern: even when companies confirm that no funds were taken and no secret keys or recovery phrases were released, the exposure of email addresses and the ability to reach subscribers can still provide a platform for repeated social engineering.



What to watch next: breach scope and future targeting


Brevo’s report indicates that the attack relied on a failure in access controls tied to single sign-on invitations, but the company’s account-by-account impact remains partially detailed. Readers should watch for additional confirmation of which customer lists were actually exported or contacted, and whether attackers can reuse the exposed addresses for follow-on campaigns.



https://www.cryptobreaking.com/brevo-login-flaw-used-to/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Brevo%20Login%20Flaw%20Used%20to%20Phish%20347K%20Trezor%20Users%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...