LOOK CRYPTO · DATA PIPELINE

Data collection status

Checking collection status…

← All news
CRYPTO NEWS

Brevo Login Flaw Enabled Phishing Attack Targeting 347K Trezor Subscribers

Cointelegraph · Ezra Reguerra

An attacker exploited a login flaw in email platform Brevo to access 138 client accounts, enabling a phishing email to reach approximately 347,000 Trezor newsletter subscribers. Similar fraudulent emails were also sent from accounts belonging to hardware wallet maker BitBox and crypto portfolio tracker and tax platform CoinTracking. The affected companies issued warnings to their users while investigations continue.

Discovery and Attack Methodology

On Thursday, Brevo published a postmortem revealing that the attacker created a Brevo account, enabled single sign-on (SSO), and invited legitimate Brevo users to join the configuration. While access was supposed to be limited to one organization, a failure in authorization boundaries granted access to all organizations accessible to the invited users.

The attacker exploited this flaw to export contacts from 43 accounts and send phishing emails from 6 accounts. Another 93 accounts showed no significant activity.

Brevo did not specify whether these account categories overlapped.

Trezor’s Response and Impact

Trezor reported the phishing email was titled "Critical Security Alert: STM32 Entropy Vulnerability" and contained a link to a fraudulent app requesting users’ wallet backups.

The company disabled the malicious domain at the DNS level within 20 minutes; nevertheless, about 2,500 users clicked the link before takedown.

According to a Trezor spokesperson, the initial email was sent to 347,000 customers, all of whom were informed about the risk.

Trezor’s Brevo account stored only opted-in newsletter email addresses, no other personal customer data. Until Brevo provides more details, Trezor treats all roughly 347,000 newsletter addresses as compromised and potentially at risk of phishing.

BitBox and CoinTracking Involvement

BitBox and CoinTracking confirmed phishing emails were also sent via their Brevo accounts.

BitBox stated that their stored data only included email addresses and language preferences, with no company credentials, contacts downloads, lost funds, or recovery phrases compromised.

They are treating the contact list as potentially accessed pending Brevo’s further log information.

CoinTracking reported sending an email titled "Data Breach Notice: Please refresh API Keys as soon as possible," warning recipients not to follow any links contained therein.

Why it matters

This incident highlights the critical importance of robust security measures within email marketing platforms that underpin communication channels for cryptocurrency firms. The Brevo login flaw allowed an attacker to compromise a substantial number of subscribers of prominent brands, creating a direct risk of wallet backup theft via phishing links. Particularly concerning is the broken single sign-on and authorization boundary, emphasizing the necessity for stringent access controls and organizational isolation within such services. This breach serves as a cautionary tale for the crypto industry to enhance oversight and continuous monitoring of third-party providers responsible for user communications, preventing large-scale data exposure and fraudulent campaigns.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗