Brevo Email Platform Breach Leads to Phishing Attack on Trezor Subscribers
- An attacker exploited a flaw in Brevo’s login system, accessing 138 client accounts.
- Approximately 347,000 Trezor newsletter subscribers received phishing emails, with about 2,500 clicking malicious links.
- The phishing email claimed to address a “Critical Security Alert” and requested users’ wallet backups.
- BitBox and CoinTracking also had unauthorized emails sent from their accounts via Brevo.
- Brevo reported that six accounts were used to send the phishing emails, with contacts exported from various accounts.
The breach highlights vulnerabilities in email platforms that can lead to significant risks for cryptocurrency firms and their customers. Trezor has advised all affected subscribers to be cautious of potential phishing attempts using their email addresses.
With about 347,000 newsletter addresses potentially exposed, companies are taking precautions while awaiting further details from Brevo regarding the incident.