A significant security breach involving the email platform Brevo has led to phishing attacks targeting approximately 347,000 Trezor subscribers. The incident highlights vulnerabilities in third-party service providers used by crypto firms.
Details of the Breach
According to Trezor, the phishing email was disseminated after an attacker exploited a flaw in Brevo’s login system, gaining access to 138 client accounts. This breach allowed the attacker to send fraudulent emails not only through Trezor but also via accounts belonging to BitBox and CoinTracking.
Brevo’s postmortem indicated that six accounts were utilized to send the phishing emails. Contacts were exported from 43 accounts, while 93 accounts showed no significant activity. The platform did not clarify whether these categories overlapped.
Phishing Campaign Details
The phishing email, titled “Critical Security Alert: STM32 Entropy Vulnerability,” contained a link prompting users to provide their wallet backups. Trezor acted swiftly, disabling the malicious domain within 20 minutes, though around 2,500 users accessed the link before it was taken down.
A spokesperson for Trezor confirmed that all subscribers were notified about the potential risks associated with the phishing attempt, emphasizing that the Brevo account only stored opt-in newsletter email addresses without any additional customer data.
Responses from Affected Companies
Both BitBox and CoinTracking confirmed their involvement in the incident. A BitBox representative stated that their unauthorized email reached its entire newsletter and tutorial list, but they found no evidence of compromised credentials or lost funds. They are treating their email list as potentially accessed while awaiting further information from Brevo.
CoinTracking reported that their Brevo account sent an email titled “Data Breach Notice: Please refresh API Keys as soon as possible,” advising recipients against clicking any links included in the message.
Implications for Data Security
This incident underscores the risks associated with relying on third-party services for critical operations in the crypto sector. As firms like Trezor and BitBox navigate the fallout, the need for robust security measures and transparent communication with users becomes increasingly evident.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








